Malicious Google Ads Hit Crypto Users With Wallet Drainers
ID: a0c580fc-28fe-5814-ac5f-695186b42b02
STIX ID: report--a0c580fc-28fe-5814-ac5f-695186b42b02
Feed Name: GBHackers
Threat Score
SEAL reports an active, technically advanced campaign abusing Google Ads and trusted Google properties to serve JavaScript drainers and cloned wallet sites that harvest seed phrases and drain cryptocurrency; attackers use cloaking, fingerprinting, Arweave/Cloudflare hosting, chained iframes and a proxy layer to evade detection and tailor thefts, with hundreds of malicious ad URLs observed and multiple drainer-as-a-service families (e.g., Inferno Drainer, Vanilla Drainer) implicated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
