Scammers using fake Authenticator impersonate Google on Google Ads

Published:

spot_img

Hackers Impersonate Google on Ads to Distribute Malware: How the Scam Works

Hackers are taking advantage of Google Ads to impersonate Google and deceive users into downloading malware disguised as the Google Authenticator. These malicious ads, which appear to be verified by Google, are part of a growing trend of brand impersonation on the platform.

According to a report by Malwarebytes Labs, innocent victims searching for the Google Authenticator may unknowingly install malware on their devices. The scam works by presenting fake ads that mimic official sources, with verified advertiser identities. In one example, the ad for the Google Authenticator displayed the official Google website and a legitimate description, but the advertiser, “Larry Marr,” was found to be fake.

Upon clicking the ad, users are redirected through multiple intermediary domains controlled by the attacker, eventually landing on a fake Authenticator site. The fraudulent site then prompts users to download a file named Authenticator.exe from GitHub, signed by an unknown company, Songyuan Meiying Electronic Products Co., Ltd.

The downloaded file contains DeerStealer malware, designed to steal personal data from the victim’s computer. The threat actor utilized GitHub as a trusted cloud resource to host the malware, exploiting the platform’s credibility. Malwarebytes Labs warns against downloading software from ads and recommends visiting official repositories directly.

This incident highlights the prevalence of scammers using verified status on Google Ads to deceive users. Similar scams have been reported on other platforms like Facebook. As cybersecurity threats continue to evolve, it is crucial for users to exercise caution and verify the legitimacy of sources before downloading any software.

spot_img

Related articles

Recent articles

Transforming Care Excellence: The Heart of KFSHRC’s Command Center

Transforming Healthcare Efficiency at King Faisal Specialist Hospital Capacity Command Center: A Technological Leap The King Faisal Specialist Hospital & Research Centre (KFSHRC) is at the...

PathWiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack

New Threats to Ukrainian Critical Infrastructure: The Emergence of PathWiper Malware In a significant escalation in the ongoing cyber conflict, researchers from Cisco Talos have...

Unveiling the Dark Web Dealer Linked to Ross Ulbricht’s $31 Million Bitcoin Gift

Bitcoin Donation to Ross Ulbricht: A Closer Look Overview of the Donation Last weekend, Ross Ulbricht made headlines when he received an astonishing Bitcoin donation valued...

Exclusive: NSW Petroleum Distributor Allegedly Hacked by World Leaks Group

Cyber Attack Allegations: Kel Campbell Distributors Targeted by Hacking Group In a recent development, reports have emerged about a cyber attack on Campbell Petroleum Distributors,...