logo

A surge of malvertising across Google Ads is distributing dangerous malware

ID: a9a47c19-8797-54b3-af76-e9da9cd9e7f9

STIX ID: report--a9a47c19-8797-54b3-af76-e9da9cd9e7f9

Feed Name: The Spamhaus Project

Threat Score
70/100

Date Published: 2023-02-02

Date Updated: 2026-04-30

Author: Sarah Miller

...
...

Security researchers (abuse.ch and The Spamhaus Project) observed a surge in Google Ads-based malvertising campaigns that impersonate services like Mozilla Thunderbird and Microsoft Teams to deliver malware (IcedID, MetaStealer) and link to lookalike/typo domains associated with stealers such as Aurora Stealer and Vidar; the actors are using typosquatted and fake domains to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.