logo

Malicious Google Ads Hit Crypto Users With Wallet Drainers

ID: a0c580fc-28fe-5814-ac5f-695186b42b02

STIX ID: report--a0c580fc-28fe-5814-ac5f-695186b42b02

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SEAL reports an active, technically advanced campaign abusing Google Ads and trusted Google properties to serve JavaScript drainers and cloned wallet sites that harvest seed phrases and drain cryptocurrency; attackers use cloaking, fingerprinting, Arweave/Cloudflare hosting, chained iframes and a proxy layer to evade detection and tailor thefts, with hundreds of malicious ad URLs observed and multiple drainer-as-a-service families (e.g., Inferno Drainer, Vanilla Drainer) implicated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.