PULSE NAME
Attackers Use Fake Google Ads to Steal Google Ad Accounts
WHITE eric.ford 2025-01-16 Modified: 2025-01-16
29
IOCs
MEDIUM VOLUME
This blog post from Malwarebytes analyzes a malvertising campaign where cybercriminals use fake Google Ads to phish organizations and steal their advertiser account credentials. The widespread nature of this operation poses significant risks, including unauthorized access to advertising budgets and the potential dissemination of additional malware or scams. The attack begins with a fraudulent ad that mimics a legitimate Google Ad, leading victims to a phishing page hosted on Google Sites that closely resemble authentic Google login pages. Once credentials are obtained, these accounts are either sold on blackhat forums or exploited to further propagate malicious advertising campaigns. Cybersecurity professionals are advised to implement multifactor authentication (MFA) for all advertising accounts, educate users about the dangers of clicking on sponsored search results, and monitor for unusual account activity to mitigate these threats.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (29)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain account-costumers.site 2025-01-16
domain accounts-ads.site 2025-01-16
domain ads-goo.click 2025-01-16
domain ads-goog.link 2025-01-16
domain ads-overview.com 2025-01-16
domain adsettings.site 2025-01-16
domain adsgsetups.shop 2025-01-16
domain advertsing-acess.site 2025-01-16
domain advertsing-v3.site 2025-01-16
domain benephica.pt 2025-01-16
domain cacaobliss.pt 2025-01-16
domain colegiopergaminho.pt 2025-01-16
domain docs-pr.top 2025-01-16
domain tmcampos.pt 2025-01-16
hostname account-worda-ads.benephica.com 2025-01-16
hostname account-worda-ads.cacaobliss.pt 2025-01-16
hostname account.universitas-studio.es 2025-01-16
hostname accounts.google.lt1l.com 2025-01-16
hostname accounts.goosggles.com 2025-01-16
hostname accounts.lichseagame.com 2025-01-16
hostname accousnt-ads.tmcampos.pt 2025-01-16
hostname accousnt.benephica.pt 2025-01-16
hostname accousnt.hyluxcase.me 2025-01-16
hostname accousnt.whenin.pt 2025-01-16
hostname ads-google.io-es.com 2025-01-16
hostname ads1.google.lt1l.com 2025-01-16
hostname ads1.google.veef8f.com 2025-01-16
hostname as.vn-login.shop 2025-01-16
hostname vietnamworks.vn-login.shop 2025-01-16