← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Attackers Use Fake Google Ads to Steal Google Ad Accounts
This blog post from Malwarebytes analyzes a malvertising campaign where cybercriminals use fake Google Ads to phish organizations and steal their advertiser account credentials. The widespread nature of this operation poses significant risks, including unauthorized access to advertising budgets and the potential dissemination of additional malware or scams. The attack begins with a fraudulent ad that mimics a legitimate Google Ad, leading victims to a phishing page hosted on Google Sites that closely resemble authentic Google login pages. Once credentials are obtained, these accounts are either sold on blackhat forums or exploited to further propagate malicious advertising campaigns. Cybersecurity professionals are advised to implement multifactor authentication (MFA) for all advertising accounts, educate users about the dangers of clicking on sponsored search results, and monitor for unusual account activity to mitigate these threats.
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | account-costumers.site | — | 2025-01-16 | |
| domain | accounts-ads.site | — | 2025-01-16 | |
| domain | ads-goo.click | — | 2025-01-16 | |
| domain | ads-goog.link | — | 2025-01-16 | |
| domain | ads-overview.com | — | 2025-01-16 | |
| domain | adsettings.site | — | 2025-01-16 | |
| domain | adsgsetups.shop | — | 2025-01-16 | |
| domain | advertsing-acess.site | — | 2025-01-16 | |
| domain | advertsing-v3.site | — | 2025-01-16 | |
| domain | benephica.pt | — | 2025-01-16 | |
| domain | cacaobliss.pt | — | 2025-01-16 | |
| domain | colegiopergaminho.pt | — | 2025-01-16 | |
| domain | docs-pr.top | — | 2025-01-16 | |
| domain | tmcampos.pt | — | 2025-01-16 | |
| hostname | account-worda-ads.benephica.com | — | 2025-01-16 | |
| hostname | account-worda-ads.cacaobliss.pt | — | 2025-01-16 | |
| hostname | account.universitas-studio.es | — | 2025-01-16 | |
| hostname | accounts.google.lt1l.com | — | 2025-01-16 | |
| hostname | accounts.goosggles.com | — | 2025-01-16 | |
| hostname | accounts.lichseagame.com | — | 2025-01-16 | |
| hostname | accousnt-ads.tmcampos.pt | — | 2025-01-16 | |
| hostname | accousnt.benephica.pt | — | 2025-01-16 | |
| hostname | accousnt.hyluxcase.me | — | 2025-01-16 | |
| hostname | accousnt.whenin.pt | — | 2025-01-16 | |
| hostname | ads-google.io-es.com | — | 2025-01-16 | |
| hostname | ads1.google.lt1l.com | — | 2025-01-16 | |
| hostname | ads1.google.veef8f.com | — | 2025-01-16 | |
| hostname | as.vn-login.shop | — | 2025-01-16 | |
| hostname | vietnamworks.vn-login.shop | — | 2025-01-16 |