Scammers Use Google Ads to Deliver Fake Security Alerts, Lock Browsers
A sophisticated tech support scam kit is using Google Ads to deliver fake security alerts that lock browsers and evade automated analysis, according to Netskope Threat Labs.
The campaign was observed across at least 619 organizations between August 31 and September 14, with the majority being in the United States (62%), followed by Japan (16%) and Australia (14%).
The ads appeared on legitimate publisher sites, including maps, weather, real-estate, document-hosting, and sports sites, through paid Google Ads rather than organic searches.
After clicking an ad, users see a loading spinner with 'Cancel' and 'Continue' buttons before the page turns into an ordinary-looking online store branded 'ShopEase'. The kit waits for a mouse movement to trigger its hidden code, which runs two decryption stages to recover a command-and-control address and decrypt a fake security locker.
The decrypted locker imitates Microsoft Defender on Windows or Apple storefront on macOS, displaying a fake scan claiming the computer is infected. Users are pressured into calling a support number displayed on the screen, but Netskope warns that the computer itself is not locked, and operating-system controls remain available.