logo

Hackers use Google Search ads to steal Google Ads accounts

ID: 98c17938-eb66-573e-81d6-fc7ebd9b403d

STIX ID: report--98c17938-eb66-573e-81d6-fc7ebd9b403d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-15

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Threat actors are running malicious Google Search ads that redirect victims to phishing pages hosted on Google Sites, impersonating the Google Ads login to harvest credentials; stolen advertiser accounts are then used to run fraudulent ad campaigns, drained of budget, or sold on criminal forums. Malwarebytes observed multiple actor clusters (Portuguese-speaking likely in Brazil, Asia-based using Hong Kong/China accounts, and Eastern European groups) and describes a multi-stage attack flow including credential capture, addition of rogue admins, and account takeover, indicating an ongoing, widespread malvertising campaign affecting potentially thousands of advertisers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.