Attackers Abuse Google Ad Feature to Target Slack, Notion Users
ID: be62d94f-f72f-5499-aa1d-a6b81eec8fc8
STIX ID: report--be62d94f-f72f-5499-aa1d-a6b81eec8fc8
Feed Name: Dark Reading
Date Published: 2024-04-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
**Executive Summary:** Attackers abused Google Ads' ad-tracking feature to display banners for popular collaboration tools (Slack, Notion, Trello, etc.) that redirected users via hidden tracking URLs to malicious landing pages; victims were lured to download Inno Setup/NSIS installers which deployed the Rhadamanthys stealer (injected into %system32%) to exfiltrate browser data and system information, and researchers published associated URLs and IoCs for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
