logo

Hackers Abuse Google Discover With AI-Generated Content to Push Malicious Notifications

ID: ed285f51-e5d0-59d4-b825-446fa76b9fc5

STIX ID: report--ed285f51-e5d0-59d4-b825-446fa76b9fc5

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers uncovered a large-scale campaign called "Pushpaganda" that injects AI-generated, sensationalized content into Google Discovery feeds to lure users to actor-controlled domains; once clicked, deceptive notification prompts and JavaScript tab-rotation techniques subscribe users to persistent, OS-level push-notification streams that bypass ad blockers and deliver fraudulent alerts and scams. The operation leveraged 113 domains, produced massive ad-bid activity, used deepfakes and deceptive UI to drive clicks and ad revenue fraud, and expanded across multiple countries before researchers reported the domains to Google and a mitigation was deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.