Comp-U-News from Comp-U-Talk

October 2026


There are only two types of companies: “those that have been breached and know it and those that have been breached and don’t know it.” ~Ted Schlein


I learned something in September.  I hate it when that happens!  I’m just ambling thru my day and suddenly something jumps out and says ”You Need To Learn This!”   “NOW!!”  And why is the learning always focused on something negative?  I hate that!

So, this is what went down:  A customer was having problems with a printer.  Said person did due diligence and turned everything off and turned everything on.  Looked for directions/suggestions online and found the manufacturer’s phone number, called “manufacturer” and was transferred to English-as-a-Second-Language speaking tech support team.  Tech support team asked for remote access, which was granted.  Tech Support team presented a “contract” for services.    And this is where it got scary!

Several pages of legitimate contract speak and a promise of unlimited tech support for $1299. You can see the sanitized version of the contract at https://comp-u-talk.com/scum-bag-expert/  Printer is still not functioning.  Credit card has been charged..

Fortunately, the end user had subscribed to our “Hacker-Hunters” service, and Huntress locked the system down before more damage could be done.  Here is what happened behind the scenes.

At 2026-09-21 Huntress detected activity consistent with a technical support scam on host “DESKTOP”. The user initiated a Quick Assist remote access session, followed approximately one hour later by the execution of a specific netstat command commonly used by tech support scammers to deceive users into believing their system is compromised.

The activity began when the user launched Quick Assist, Microsoft’s legitimate remote assistance tool, at 21:47:46 UTC.

At 22:47:01 UTC, the user executed the command “Netstat -sp tcp” via the Windows Command Prompt. This specific netstat command is a known tactic used by tech support scammers to display network statistics that appear alarming to non-technical users, falsely suggesting malware infection or security compromise.

Investigation revealed that the user’s browser history was deleted during the session, preventing confirmation of the scam’s origin.

The primary risk is that an unauthorized party gained remote access to this host through social engineering and may have convinced the user to provide payment information or install additional malicious software.

Threat Descriptions:

Malicious Remote Management Tool: A legitimate remote management tool has been misused by a threat actor to gain unauthorized access and control of the reported endpoint. Threat actors do this to hide their presence, maintain persistence and further exploit the network.

Fake IT Support: “Fake IT Support” scams involve fraudsters posing as technical support representatives from reputable companies. They often contact victims through unsolicited calls, emails, or pop-up messages, claiming to have detected issues with their computers or software. The scammers aim to trick victims into granting them remote access to their devices or paying for unnecessary services. These scams can lead to financial loss, data theft, and the installation of malware.

I share this story because somewhere along my life path I have learned that it is so much more convenient and way less painful to learn from someone else’s mistake, then to learn from my own mistakes.  End User was insistent he/she had called the manufacturer.  The end results say otherwise.

As we head into “National Cyber Security Awareness” Month, also known as October,  please be cautious.  I don’t care how computer savvy you are, you are just one bad day, one bad click, one brain fog moment away from making a similar mistake.  The depressing part of the story: all the tools the fraudster used are legitimate tools.  In the right hands they are completely safe and very useful.  I rely heavily on remote access tools to do my job.  Next time you are stuck, call me. I’m real, I’m legitimate, I won’t steal your savings account, and there is a good possibility that I can fix it over the phone.

If you want the security of knowing Good Guys are watching your back, reach out to me.  I can hook you up with the same service that saved the day in this story.

Also of note:  Extended service for Windows 10 stops on October 13.  What will happen on October 14? 

•Your computers will still turn on and run.  Your applications, files and day-do-day work won’t change or stop working.

•Security updates will stop.  Without updates, newly discovered vulnerabilities stay open and raises your exposure to malware and ransomware.

•Compliance and Insurance risk goes up.  Many cyber insurance policies and industry regulations expect supported, patched operating systems. 

•Software and hardware vendors will increasingly drop Windows 10 support, so you may see compatibility issues over time.

If you need help upgrading your computer or replacing your computer, come see us.  We can help you out.

Stay Safe and Happy Fall,

Janet

Leave a Reply