Cyber Security News

Hackers Exploiting Companies’ Google Ads Accounts To Serve Malicious Ads

In a disturbing trend that has gained momentum since late 2024, cybercriminals are increasingly targeting Google Ads accounts belonging to legitimate businesses to serve malicious advertisements.

This sophisticated attack vector, known as malvertising, poses a significant threat to both advertisers and internet users alike.

The scheme involves threat actors compromising Google Ads accounts and using them to create deceptive ads that appear legitimate but lead users to phishing sites or malware-laden downloads.

A malicious ad masquerading as Google Ads (Source – MalwareBytes)

By leveraging the reputation of established companies, these malicious ads often bypass Google’s initial security checks.

Cybersecurity researchers at Malwarebytes have identified multiple campaigns utilizing this tactic. One notable operation impersonates popular software products like Grammarly, Slack, and AnyDesk.

When users click on these ads, they are redirected to convincing clone websites where they unknowingly download trojanized versions of the software, potentially infecting their systems with various types of malware.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Evasion Techniques

The attackers employ sophisticated techniques to evade detection:

  1. Using Google Sites to host intermediate landing pages, making the ads appear more legitimate.
  2. Implementing cloaking and anti-bot measures to hide malicious content from security scanners.
  3. Exploiting Google Ads’ tracking templates to selectively target victims while redirecting others to legitimate sites.
Process flow (Source – MalwareBytes)

Perhaps most concerning is the apparent difficulty in shutting down these operations. Researchers have reported instances where the same compromised advertiser accounts were used repeatedly, even after being flagged multiple times.

The impact of these attacks is far-reaching. Not only do they put users at risk of data theft and malware infection, but they also damage the reputation of the companies whose accounts are compromised.

The same ad found in different countries (Source – MalwareBytes)

Additionally, the stolen ad budgets further fund criminal activities. Experts advise both advertisers and users to take precautions:

For advertisers:-

  • Implement strong account security measures, including two-factor authentication.
  • Regularly monitor ad campaigns for suspicious activity.
  • Be cautious of phishing attempts targeting ad account credentials.

For users:-

  • Exercise caution when clicking on sponsored search results, even for familiar brands.
  • Verify software downloads by visiting official websites directly rather than through ads.
  • Keep security software up-to-date to detect potential threats.

However, Google actively investigating and working to address the issue, but the sophisticated nature of these attacks presents a significant challenge.

So, the continued vigilance and cooperation between platforms, advertisers, and users is must to combat these evolving cyber threats.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago