Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft
ID: 37ee1900-c345-5395-aac1-fd3858b32895
STIX ID: report--37ee1900-c345-5395-aac1-fd3858b32895
Feed Name: cybersecurityNews.com
SecurityAlliance (SEAL) documents a widespread 2026 campaign in which criminals weaponize Google Ads to impersonate major crypto services (e.g., Uniswap, Morpho, Ledger) and deliver wallet-draining JavaScript, seed-phrase stealers, and fake browser extensions via trusted Google domains, hidden iframes, fingerprinting, and man-in-the-middle proxies; SEAL blocked 356 malicious ad URLs and attributes at least $1.27M in confirmed thefts during mid‑March 2026 while urging users to access crypto sites only via bookmarked trusted URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
