Google Ads logo and money showing malvertising campaign targeting advertiser accounts

“Most Egregious” Malvertising Campaign Uses Google Ads to Steal Advertiser Accounts

Hackers are using Google Ads to direct victims to phishing sites that steal advertiser accounts in the “most egregious malvertising campaign” tracked by cybersecurity firm Malwarebytes.

The campaign starts by placing malicious ads targeting businesses and individuals who use Google ads or are interested in the service.

Clicking the ads redirects the victims to a fake Google Ads onboarding page hosted on Google Sites, Google’s free website hosting platform, sites.google.com.

Google Sites allows the attackers to conceal their malicious activity because the URL matches Google Ads’ root domain, ads.google.com, and Google requires the destination URL to match the ad’s URL.

“Indeed, you cannot show a URL in an ad unless your landing page (final URL) matches the same domain name. While that is a rule meant to protect abuse and impersonation, it is one that is very easy to get around,” said Jérôme Segura, Senior Director of Research at Malwarebytes.

Clicking the ‘login’ or ‘start now’ button redirects the victims to an actual phishing site that collects their credentials, unique identifiers, and cookies using an embedded JavaScript phishing kit.

How hackers use Google Ads to take over advertiser accounts

Victims with existing Google Ads accounts receive notifications about suspicious logins from an unusual location, usually in Brazil in South America. Malwarebytes researchers also identified threat actors in Asia (Hong Kong or China) and Eastern Europe.

If they fail to act immediately, ignore the alert, or receive it late, a new administrator is added to their advertiser accounts using a different email address. The rogue administrator then embarks on a spending spree using the funds in their advertiser account or even locks them out if possible.

Malwarebytes believes the attackers’ objective is to sell the compromised accounts to other threat actors while reserving some for their own use in running fake Google ads to propagate the malvertising campaign.

“The fake ads for Google Ads come from a variety of individuals and businesses (including a regional airport), in various locations,” Segura added. “Some of those accounts already had hundreds of other legitimate ads running.”

By taking over well-established advertiser accounts, the attackers circumvent Google’s Limited Ads Serving policy which limits the reach of new publishers’ ads until they complete the “get-to-know-you” period.

Social media complaints and Google support requests suggest the campaign has been active since November 2024.

“This is the ultimate full-circle social engineering scam. Scam advertisers so they can take over their accounts so they can scam other advertisers and victims,” said Roger Grimes, data-driven defense evangelist at KnowBe4. “It also demonstrates that everyone, regardless of role, can be a potential social engineering scam target.”

Malwarebytes did not provide the number of advertiser accounts compromised but described the campaign as one of the “most egregious.”

“This is the most egregious malvertising operation we have ever tracked, getting to the core of Google’s business and likely affecting thousands of their customers worldwide,” noted Malwarebytes.

Google fighting malvertising campaigns

Meanwhile, the internet giant says it was aware of the malvertising campaign and is taking enforcement action against advertiser accounts that publish fake Google ads to trick users.

The company has already removed over 3.4 billion Google ads and restricted over 5.7 billion others, including 206.5 million blocked for breaching its misrepresentation policy and 273.4 million for violating its financial services policy. It has also suspended over 5.6 million advertiser accounts for various violations.

Nonetheless, malicious actors persistently devise new tactics to circumvent various restrictions on displaying fake ads, which is why Google has integrated AI to detect malicious campaigns.

“Until Google gets this one figured out technically, advertisers need to be educated on how to recognize these ad-based phishing attacks and how to appropriately mitigate and report them,” concluded Grimes.