Fake Artefacts & Interface Deception
Fake artefacts and interface deception uses an attacker-controlled interface, file, message, link, code, warning, or technical-looking artefact to make an action appear legitimate or safe. The artefact may imitate a login page, system alert, collaboration service, support workflow, document, QR-code process, or software update.
The technique concerns the deceptive surface used to drive an action. The resulting outcome may be credential capture, consent, payment, disclosure, software execution, remote access, or movement into another attacker-controlled workflow.
Fake artefacts and interface deception can be assessed by asking:
- What interface, file, notification, link, code, or technical artefact is being presented?
- What real service or workflow does it resemble?
- What action does it ask the user to complete?
- Can the action be reached and verified through the organisation’s established service or application instead?
Techniques
Section titled “Techniques”Fake Artefacts & Interface Deception includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T008.001Fake Authentication InterfacesMimicking login, SSO, MFA, or identity verification interfaces to capture credentials, approvals, or authentication material.
- SE-T008.002Fake System Notifications & WarningsUsing fake service alerts, browser warnings, endpoint notices, security-product messages, or operational notifications to drive an unsafe action.
- SE-T008.003Malicious Attachment & File LuresUsing files or attachments that appear legitimate, important, or work-related.
- SE-T008.004Deceptive Links & RedirectsConcealing malicious or deceptive destinations behind trusted-looking links, redirects, buttons, or shortened URLs.
- SE-T008.005Fake Support & Troubleshooting InterfacesPresenting fake support, troubleshooting, repair, or technical assistance workflows.
- SE-T008.006Fake Collaboration & Communication ServicesMimicking trusted communication, collaboration, or file-sharing platforms.
- SE-T008.007QR-Code Workflow DeceptionUsing a QR code to transfer the target into an attacker-controlled mobile, payment, authentication, information, or support workflow.
- SE-T008.008Malicious Software & Remote-Access Tool InstallationPersuading a target to install or run attacker-supplied software or grant a remote-access session.
Behavioural Indicators
Section titled “Behavioural Indicators”Fake artefacts and interface deception activity may involve one or more of the following behaviours:
Interface and artefact presentation
- mimicking trusted interfaces, services, portals, login pages, support tools, or collaboration platforms
- using realistic branding, logos, templates, colour schemes, buttons, icons, certificates, or technical language
- copying the appearance of a known vendor, platform, internal service, or security workflow
- presenting fake warnings, errors, updates, alerts, scans, consent screens, or verification prompts
- using QR codes, mobile workflows, attachments, links, or redirects to hide the destination or requested action
Request and interaction behaviour
- directing users to portals, files, QR codes, approval prompts, consent screens, downloads, or remote sessions
- asking users to enter credentials, MFA codes, recovery codes, device codes, payment details, or sensitive information
- encouraging downloads, file opening, macro enablement, app consent, remote support, browser prompts, or software installation
- persuading the user to install or run attacker-supplied software, a fake update, or a “fix tool”, or to grant a live remote-access session
- presenting activity as secure, encrypted, compliant, approved, time-sensitive, or officially required
- asking users to ignore, dismiss, disable, or bypass browser, endpoint, mail, or platform warnings
Pressure and trust indicators
- exploiting trust in technical systems, security notifications, collaboration platforms, or familiar brands
- using urgency, fear, curiosity, authority, social proof, or familiar interface patterns to reduce scrutiny
- making the artefact look routine, expected, automated, or generated by a trusted system
- combining technical-looking evidence with business pressure, such as invoice, HR, payroll, document, security, or supplier context
Timing and delivery indicators
- sending technical artefacts during busy periods, after hours, incidents, onboarding, payroll cycles, recruitment, supplier changes, or account-maintenance windows
- delivering the same deceptive portal, QR code, attachment, or warning to multiple users or teams
- moving users from email or chat into a browser, mobile device, file download, app consent flow, or remote support session