Security1 publisher2 min readPublished
Malwarebytes found AI handover notes left in the code of a fake Avast renewal page
Malwarebytes says the fake Avast renewal page it found aimed at Belgian users was noticeably more polished than most scam sites, with clean French copy, an Active status badge and a form that asks only for a name, an email address and a phone number.
The Watch · Security desk

What happened
- A scam page found by Malwarebytes told Belgian visitors that their Avast Premium Security subscription had renewed for EUR 129.99, covered five devices, and would renew again the following February.
- The lure starts with a message claiming an automatic renewal, and the cancellation instructions route the recipient to the page; the charge it references is invented.
- The only interactive element is a cancellation form collecting a full name, an email address and a Belgian mobile number.
- Two notes in polite French were left in the page code, telling whoever commissioned the work that the form did not yet send anything anywhere and that a submission process still had to be connected.
- Malwarebytes assessed the page as most likely half-built, or a template waiting to be sold on to someone who would add a destination for the stolen details.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Awareness advice built on typos and broken layout is useless here: the copy is grammatically correct, and the giveaways Malwarebytes found were in the source code, which a victim does not read.
- exposure The exposed asset is the phone line. A name and a live mobile number put the target in a queue for a support call that asks for remote access software.
- capability With the skill floor for building these pages lowered, the limit on this scam becomes who can supply mailing lists and callers to work the submissions.
- contradiction Malwarebytes rates the page more polished than most, yet says nobody had loaded it in a browser.
The page asks only for contact details. Malwarebytes said the absent password field and card fields may be deliberate, because a form asking only for a name, an email address and a phone number can feel harmless and is far easier to fill in than a login page [7][8]. "The form is the lure, and the call is where the real danger begins," the company wrote [9].
The call is where a victim loses money. Harvested details can be sold to other scammers or used for the next stage, Malwarebytes said, with someone phoning the victim as support staff and trying to get remote access software installed, or to help reverse a payment that never happened [11]. A working mobile number attached to a real name is the prerequisite for that call [10]. Answering at all makes the record more valuable, because it confirms the number is live and the person engages [12].
The signs of how it was built sit in the source. The two French notes read like a contractor handing over an unfinished job, Malwarebytes said, and that courteous, second-person summary of what still needs doing is how an AI assistant signs off [17]. The file also held styling for a section that had been removed, which the company said suggests the page was produced in stages without a final review [18]. The copy is grammatically correct: four paragraphs on the benefits of the subscription that never mention a specific Avast feature such as the firewall, the VPN or the ransomware protection [19]. Generated code is unmarked, Malwarebytes said, so the files alone cannot establish who wrote the page [20].
Each completed submission would have handed the operator four things: the three form fields, plus the knowledge that this person answers a message about an antivirus payment [13]. None of it reached anyone here: the form sent nothing anywhere [21][25]. Two pieces of text would have displayed as visible gibberish if anyone had opened the page in a browser, according to Malwarebytes [22].
Receiving a message that names your antivirus software does not mean the sender has access to your device or account, Malwarebytes said, because scammers send the same text to large numbers of people knowing some recipients will be customers [15]. The page is unconnected to Avast, whose branding is being used without permission [5].
What to watch
- Whether a finished version of this template appears with a working submission endpoint, and where the data lands.
- Whether the same French-language kit shows up under other antivirus brands or in other markets.
- Whether the callback stage tied to these pages is linked to an identified tech-support fraud operation.