Google Ads Used in Phishing Campaign Targeting Ledger Users
Threat actors have been using malicious Google ads to target Ledger hardware wallet users. In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used these fraudulent ads to direct users through Google Cloud Storage and Vercel to a Google Sites page displaying a phishing site in an iframe.
The phishing site mimicked the official Ledger interface and offered downloads for Windows, macOS, Linux, and mobile devices. It collected device metadata and monitored user interactions like keypresses, touches, and mouse movements, sending this data to a Vercel-hosted endpoint.
The phishing page also included a Cloudflare Web Analytics beacon configured with an analytics token. It prompted users for their secret recovery phrases, which attackers could use to access their wallets without the physical devices.