Google Ads used for scareware and Ledger phishing
Netskope and Zscaler separately reported Google Ads used for browser scareware fraud and Ledger recovery-phrase phishing.
Netskope Threat Labs reported browser scareware delivered through paid Google Ads from August 31 to September 14, 2026, spanning more than 250 campaign IDs on at least 284 legitimate publisher sites and 457 scam hosts, involving 619 organizations. After a mouse movement, pages decrypted a hidden address and rendered in-memory fake Microsoft Defender or Apple alerts that forced full-screen mode or hid the cursor and swallowed exit keys without locking the computer; opening the page did not install malware, and callers were pushed to pay, share financial or personal information, or grant remote access. The sources disagree slightly: Cyber Security News described ad-click shares of about 62% United States, 16% Japan, and 14% Australia and said infections or losses were unconfirmed, while Ars Technica said about 62% of the organizations were in the United States, with Japan and Australia next, and that Netskope blocked the content so none of those customers were scammed. Separately, Zscaler ThreatLabz reported malicious Google ads impersonating Ledger—possibly via a compromised verified German advertiser account—that routed users through Google Cloud Storage, Vercel, and Google Sites to a fake page whose Vercel domains rotated about every 15-20 minutes and twice collected BIP-39 recovery phrases. Zscaler did not link that wallet-phishing activity to the Netskope scareware campaign.
- Netskope Threat Labs reported paid Google Ads scareware from August 31 to September 14, 2026, using more than 250 campaign IDs on at least 284 legitimate publisher sites and 457 scam hosts.
- Users tied to 619 organizations were exposed or clicked; Cyber Security News said there were no confirmed infections or losses, while Ars Technica said Netskope blocked the content so none of those customers were scammed.
- Pages waited for mouse movement, decrypted a hidden address, and showed in-memory fake Microsoft Defender or Apple alerts that forced full-screen mode or hid the cursor and swallowed exit keys without locking the computer.
- Opening the page did not install malware; callers were urged to pay, share financial or personal details, or grant remote access.
- Geography differs by source: Cyber Security News put ad clicks at about 62% United States, 16% Japan, and 14% Australia; Ars Technica said about 62% of the organizations were in the United States, with Japan and Australia next.
- Separately, Zscaler ThreatLabz reported Google ads impersonating Ledger, targeting the United States, Europe, and parts of Asia, with clicks routed through Google Cloud Storage, Vercel, and Google Sites.
- The fake Ledger page rotated Vercel domains about every 15-20 minutes, used a 2,048-word English autocomplete list, collected a BIP-39 recovery phrase twice, and sent both submissions to an attacker-controlled Vercel endpoint; a verified…
Coverage timelineoldest first · each row is one article
- · 1d agoGoogle Ads Campaign Spreads Fake Security Alerts That Lock Browsers and Push Malware
Cyber Security News· 55
Netskope found Google Ads scareware that fake-locks browsers and pushes victims to call fraudulent support lines.
- · 1d agoYour uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Ars Technica · Security· 58
Netskope found Google Ads delivering scareware that fake-freezes Windows and Mac browsers and pushes users toward bogus call centers.
- · 1d agoThreat Actors Use Google Ads To Target Ledger Users
Zscaler ThreatLabz· 71