Hackers use Google Search ads to steal Google Ads accounts
ID: 98c17938-eb66-573e-81d6-fc7ebd9b403d
STIX ID: report--98c17938-eb66-573e-81d6-fc7ebd9b403d
Feed Name: Bleeping Computer
Threat actors are running malicious Google Search ads that redirect victims to phishing pages hosted on Google Sites, impersonating the Google Ads login to harvest credentials; stolen advertiser accounts are then used to run fraudulent ad campaigns, drained of budget, or sold on criminal forums. Malwarebytes observed multiple actor clusters (Portuguese-speaking likely in Brazil, Asia-based using Hong Kong/China accounts, and Eastern European groups) and describes a multi-stage attack flow including credential capture, addition of rogue admins, and account takeover, indicating an ongoing, widespread malvertising campaign affecting potentially thousands of advertisers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
