Fake Google Ads Used To Steal Seed Phrases and Drain Crypto Wallets
ID: ce0d0e39-6603-54eb-8e0f-7f12f5245cc2
STIX ID: report--ce0d0e39-6603-54eb-8e0f-7f12f5245cc2
Feed Name: Cyber Press
SEAL warns of a sustained and escalating campaign in which attackers weaponize Google Ads to serve high-reputation Google-owned pages that host cloned frontends and obfuscated scripts to phish cryptocurrency users. The campaign uses cloaking, TDS filtering, Cloudflare Workers and Arweave-hosted entry pages to evade detection, and embeds a man-in-the-middle proxy (via monkey-patched fetch/XHR) to intercept Ethereum RPC calls, enabling real-time wallet monitoring and automated draining via drainer-as-a-service, hardware-wallet seed-phrase stealers, and malicious Chrome extensions; SEAL blocked 356 malicious ad URLs in a three-week window and Google has suspended identified advertiser accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
