Scammers using fake Authenticator impersonate Google on Google Ads

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Hackers Impersonate Google on Ads to Distribute Malware: How the Scam Works

Hackers are taking advantage of Google Ads to impersonate Google and deceive users into downloading malware disguised as the Google Authenticator. These malicious ads, which appear to be verified by Google, are part of a growing trend of brand impersonation on the platform.

According to a report by Malwarebytes Labs, innocent victims searching for the Google Authenticator may unknowingly install malware on their devices. The scam works by presenting fake ads that mimic official sources, with verified advertiser identities. In one example, the ad for the Google Authenticator displayed the official Google website and a legitimate description, but the advertiser, “Larry Marr,” was found to be fake.

Upon clicking the ad, users are redirected through multiple intermediary domains controlled by the attacker, eventually landing on a fake Authenticator site. The fraudulent site then prompts users to download a file named Authenticator.exe from GitHub, signed by an unknown company, Songyuan Meiying Electronic Products Co., Ltd.

The downloaded file contains DeerStealer malware, designed to steal personal data from the victim’s computer. The threat actor utilized GitHub as a trusted cloud resource to host the malware, exploiting the platform’s credibility. Malwarebytes Labs warns against downloading software from ads and recommends visiting official repositories directly.

This incident highlights the prevalence of scammers using verified status on Google Ads to deceive users. Similar scams have been reported on other platforms like Facebook. As cybersecurity threats continue to evolve, it is crucial for users to exercise caution and verify the legitimacy of sources before downloading any software.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

ATF Confirms Cyberattack by Qilin Ransomware Group Targeted Investigation Data

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack attributed to the Qilin ransomware group, which targeted investigation data. The...

Trump Administration Bans Foreign-Made Power Generation Equipment Over Cybersecurity Risks

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity and power, citing cybersecurity risks. The...

Iranian Hackers Shut Down UK Power Plant for Four Days in Unprecedented Attack

In a significant escalation of cyber warfare, Iranian hackers successfully shut down a British power plant for four days, marking a notable first for...

New Research Reveals Perturbation Probing Method to Assess LLM Safety Fragility

New Research Unveils Perturbation Probing Method to Assess LLM Safety Fragility Recent advancements in the field of large language models (LLMs) have raised critical questions...