Threat Actors Use Google Ads To Target Ledger Users
Attackers used malicious Google ads to phish Ledger users for cryptocurrency recovery phrases.
Zscaler ThreatLabz observed malicious Google search ads impersonating Ledger and targeting users in the United States, Europe, and parts of Asia. Clicks passed through Google Cloud Storage, Vercel, and Google Sites to a fake Ledger page; Vercel domains rotated about every 15-20 minutes. The page collected device and interaction data, then prompted users twice for a BIP-39 secret recovery phrase and sent both submissions to an attacker-controlled Vercel endpoint. With that phrase, attackers can restore the wallet and move funds without the physical device.
71