logo

Google ads push fake Google Authenticator site installing malware

ID: 11b7dfb3-8c0e-5495-8100-eae09b89b582

STIX ID: report--11b7dfb3-8c0e-5495-8100-eae09b89b582

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-07-31

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A malvertising campaign abused Google Search ads to impersonate Google Authenticator and redirect users to fake landing pages (e.g., chromeweb-authenticators.com and similar domains) that deliver a signed executable named "Authenticator.exe" hosted on GitHub. Executing the file launches DeerStealer, an information stealer that harvests browser credentials, cookies, and other data; the campaign uses URL cloaking and mass account creation to evade detection and even presented verified advertiser identities. The report notes code signing on multiple samples, which can help the malware bypass Windows/AV checks, and recommends avoiding promoted search results, using ad blockers, verifying official domains, and scanning downloads before execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.