Scammers finding ways to bypass Google ad checks and impersonate real brands

Published:

spot_img

Google Ads Impersonation Scams: How Malicious Actors Trick Google’s Bots

Google seems to have a problem with brand impersonation, as some ads on top of the search results bar are leading users to scams while appearing to be legitimate brands like Facebook. Malicious actors have found a way to trick Google’s bots, as reported by users and security researchers.

Justin Poliachik, a developer and creator on TikTok, shared his experience of encountering a fraudulent phishing site disguised as an official Facebook ad on Google. Despite the ad having an official Facebook URL and appearing to link to a standard Facebook login page, it redirected users to a malicious website claiming their computer was infected.

Security researchers at Malwarebytes Labs confirmed Poliachik’s findings and explained that scammers are using cloaking techniques to bypass Google’s security measures. By distinguishing real humans from bots or crawlers, malicious actors can deliver different experiences to each group, redirecting bots to legitimate domains and real users to fraudulent websites.

While Poliachik believes Google should use more AI to check links more often, researchers doubt that it would effectively combat malvertising. Instead, they suggest that Google differentiate legitimate affiliates by analyzing various data points about the advertiser, such as user profile, payment method, and ad content.

In light of these findings, users are advised to be cautious of sponsored results, block ads altogether, and learn to recognize scam pages. Malwarebytes recommends using guard extensions to enhance online security and protect against malicious advertising campaigns.

spot_img

Related articles

Recent articles

Microsoft and CrowdStrike Team Up to Solve Threat Actor Attribution Issues

Microsoft and CrowdStrike Join Forces to Improve Threat Actor Attribution In a pivotal collaboration, Microsoft and CrowdStrike are taking significant strides to address the complexities...

VAST Data Launches AI OS Designed for the Agent Era – A Security Review

Revolutionizing the Future: VAST Data's AI Operating System A Decade of Innovation In an age defined by rapid technological advancement, VAST Data has emerged as a...

Oregon Agency’s Sensitive Data Leaked on Dark Web by Ransomware Group

Ransomware Attack Exposes Data from Oregon Department of Environmental Quality Overview of the Cyberattack In a striking incident reported by Oregon Public Radio, a ransomware group...

Vulnerabilities in Ulefone and Krüger&Matz Phones: Preinstalled Apps Can Reset Devices and Steal PINs

Security Vulnerabilities in Preloaded Android Apps: A Closer Look On June 2, 2025, cybersecurity researchers disclosed three significant vulnerabilities in preinstalled Android applications found on...