logo

Attackers Hijack Google Advertiser Accounts to Spread Malware

ID: 3cef9c05-841e-5e36-b337-d5d449854f94

STIX ID: report--3cef9c05-841e-5e36-b337-d5d449854f94

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-01-15

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers at Malwarebytes identified a large-scale malvertising campaign in which attackers impersonate Google Ads (using ads that display ads.google.com and lure pages hosted on Google Sites) to phish advertiser credentials, then immediately use compromised accounts to place malicious ads and distribute malware; Google is investigating and taking down reported ads but the operators repeatedly spin up new accounts, making the activity persistent and impactful.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.