Tag: google ads

Google Ads Users Targeted in Malvertising Scam Stealing Credentials and 2FA Codes
News

Google Ads Users Targeted in Malvertising Scam Stealing Credentials and 2FA Codes

Researchers studying cybersecurity have warned of a new malvertising effort that aims to phish for users' credentials through phoney Google ads, targeting both individuals and companies that use Google Ads. Jérôme Segura, senior director of threat intelligence at Malwarebytes, told The Hacker News that the plan involves spoofing Google Ads to capture as many advertising accounts as possible and rerouting users to phony login pages. It is believed that the campaign's ultimate objective is to sell the credentials to other criminal actors on underground forums and use them again to continue the activities. Posts on Google's support forums, Bluesky, and Reddit indicate that the threat has been active since at least mid-November 2024 read more about Google Ads Users Targeted in Malvertis...
Google ads push fake Google Authenticator site installing malware
News

Google ads push fake Google Authenticator site installing malware

Due to Google's own ad platform, threat actors are now able to produce phony Google Authenticator advertisements that promote the malware that steals personal information, DeerStealer. Malicious advertising, or "malvertising," has been aimed against the Google search engine for years. Here, threat actors post advertisements pretending to be well-known software websites, with the goal of infecting users' computers with malware. Worse, threat actors can now produce Google search ads that display authentic domains, lending credibility to the advertisement. Threat actors developed advertisements for Google Authenticator in a recent malvertising campaign discovered by Malwarebytes, which appears when users search for the software on Google read more about Google ads push fake Google A...
Google ads push malicious CPU-Z app from fake Windows news site
News

Google ads push malicious CPU-Z app from fake Windows news site

A threat actor has been distributing a trojanized version of the CPU-Z tool to deliver the Redline information-stealing malware via Google Ads. The new campaign was discovered by Malwarebytes analysts, who believe it is part of the same operation that used Notepad++ malvertising to deliver malicious payloads. The malicious Google advertisement for the trojanized CPU-Z, a Windows tool for profiling computer hardware, is hosted on a cloned copy of the legitimate Windows news site WindowsReport. CPU-Z is a popular free utility that allows users to monitor various hardware components read more Google ads push malicious CPU-Z app from fake Windows news site. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the...
Malvertisers Using Google Ads to Target Users Searching for Popular Software
News

Malvertisers Using Google Ads to Target Users Searching for Popular Software

There are details available regarding a malicious campaign that uses Google Ads to spread next-stage payloads and send people looking for well-known software to fake landing pages. This behavior was found by Malwarebytes, which described it as "unique in its way to fingerprint users and distribute time-sensitive payloads." In order to deliver fake advertisements on the Google search results page that, when clicked, filter out bots and other unwanted IP addresses by displaying a spoof website, the attack targets visitors who are specifically looking for Notepad++ and PDF converters. If the threat actor thinks the visitor is interesting, it will send the victim to a spoof website that promotes the program while discreetly fingerprinting the system to find out if the request is comi...
Malicious Notepad++ Google ads evade detection for months
News

Malicious Notepad++ Google ads evade detection for months

A recent malvertising effort on Google Search uses sophisticated ways to avoid detection and analysis as it targets users who want to download the well-known Notepad++ word editor. Malicious actors have been exploiting Google Ads more frequently to advertise phony software websites that propagate malware through malvertising campaigns. The Notepad++ malvertising campaign has been active for a few months, but Malwarebytes, who first discovered it, claims that it has remained hidden for that entire period. Although the exact payload that was sent to the victims is unknown, Malwarebytes believes it was most likely Cobalt Strike read more Malicious Notepad++ Google ads evade detection for months. Stay informed with the best cybersecurity news and raise your cybersecurity awarenes...
Fake Cisco Webex Google Ads abuse tracking templates to push malware
News

Fake Cisco Webex Google Ads abuse tracking templates to push malware

Threat actors can construct convincing Webex software search ads that link users to websites that have the BatLoader malware by exploiting a flaw in Google Ads tracking templates. Worldwide enterprises and businesses utilize the video conferencing and contact center software package Webex, which is a component of Cisco's collaboration product line. According to Malwarebytes, the threat actors in the malvertising operation appear to be from Mexico, and it has been active in Google Search for a week. According to Malwarebytes, the top Google Search result for the phrase "webex" displays a malicious Google ad that pretends to be the genuine Webex download portal read more Fake Cisco Webex Google Ads abuse tracking templates to push malware. Stay informed with the best cybersecurity ...
SYS01 Stealer Targets Critical Infrastructure With Google Ads
News

SYS01 Stealer Targets Critical Infrastructure With Google Ads

From November 2022, threat actors have infected the systems of key government infrastructure workers, manufacturing organisations, and other targets with the information thief known as SYS01. Security researchers at Morphisec discovered the new effort, which used false Facebook pages to advertise games, sexual content, and cracked software while luring Facebook business accounts with Google advertisements. The enticement then prompted the download of a malicious link. Arnold Osipov, a malware researcher at Morphisec, stated in a Tuesday advisory that the attack "is meant to steal sensitive information read more SYS01 Stealer Targets Critical Infrastructure With Google Ads. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive...