Skip to content

Fake Artefacts & Interface Deception

Fake artefacts and interface deception uses an attacker-controlled interface, file, message, link, code, warning, or technical-looking artefact to make an action appear legitimate or safe. The artefact may imitate a login page, system alert, collaboration service, support workflow, document, QR-code process, or software update.

The technique concerns the deceptive surface used to drive an action. The resulting outcome may be credential capture, consent, payment, disclosure, software execution, remote access, or movement into another attacker-controlled workflow.

Fake artefacts and interface deception can be assessed by asking:

  • What interface, file, notification, link, code, or technical artefact is being presented?
  • What real service or workflow does it resemble?
  • What action does it ask the user to complete?
  • Can the action be reached and verified through the organisation’s established service or application instead?

Fake Artefacts & Interface Deception includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Fake artefacts and interface deception activity may involve one or more of the following behaviours:

Interface and artefact presentation

  • mimicking trusted interfaces, services, portals, login pages, support tools, or collaboration platforms
  • using realistic branding, logos, templates, colour schemes, buttons, icons, certificates, or technical language
  • copying the appearance of a known vendor, platform, internal service, or security workflow
  • presenting fake warnings, errors, updates, alerts, scans, consent screens, or verification prompts
  • using QR codes, mobile workflows, attachments, links, or redirects to hide the destination or requested action

Request and interaction behaviour

  • directing users to portals, files, QR codes, approval prompts, consent screens, downloads, or remote sessions
  • asking users to enter credentials, MFA codes, recovery codes, device codes, payment details, or sensitive information
  • encouraging downloads, file opening, macro enablement, app consent, remote support, browser prompts, or software installation
  • persuading the user to install or run attacker-supplied software, a fake update, or a “fix tool”, or to grant a live remote-access session
  • presenting activity as secure, encrypted, compliant, approved, time-sensitive, or officially required
  • asking users to ignore, dismiss, disable, or bypass browser, endpoint, mail, or platform warnings

Pressure and trust indicators

  • exploiting trust in technical systems, security notifications, collaboration platforms, or familiar brands
  • using urgency, fear, curiosity, authority, social proof, or familiar interface patterns to reduce scrutiny
  • making the artefact look routine, expected, automated, or generated by a trusted system
  • combining technical-looking evidence with business pressure, such as invoice, HR, payroll, document, security, or supplier context

Timing and delivery indicators

  • sending technical artefacts during busy periods, after hours, incidents, onboarding, payroll cycles, recruitment, supplier changes, or account-maintenance windows
  • delivering the same deceptive portal, QR code, attachment, or warning to multiple users or teams
  • moving users from email or chat into a browser, mobile device, file download, app consent flow, or remote support session