PULSE NAME
The great Google Ads heist: criminals ransack advertiser accounts via fake Google ads
WHITE AlienVault 2025-01-20 Modified: 2025-01-20
29
IOCs
MEDIUM VOLUME
Cybercriminals are targeting Google Ads advertisers through phishing campaigns, impersonating Google Ads via fraudulent ads. The scheme involves stealing advertiser accounts by redirecting victims to fake login pages, with the goal of reselling these accounts on blackhat forums. The operation uses compromised accounts to perpetuate the campaign, affecting thousands of Google customers worldwide. Victims include individuals and businesses looking to advertise on Google Search. The attacks involve sophisticated techniques, including the use of Google Sites for impersonation and phishing kits to collect user data. Two main groups have been identified: one based in Brazil and another in Asia, possibly China. The stolen accounts are valuable for further malvertising campaigns, scams, and malware distribution.
Indicators of Compromise (29)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain account-costumers.site 2025-01-20
domain accounts-ads.site 2025-01-20
domain ads-goo.click 2025-01-20
domain ads-goog.link 2025-01-20
domain ads-overview.com 2025-01-20
domain adsettings.site 2025-01-20
domain adsgsetups.shop 2025-01-20
domain advertsing-acess.site 2025-01-20
domain advertsing-v3.site 2025-01-20
domain benephica.pt 2025-01-20
domain cacaobliss.pt 2025-01-20
domain colegiopergaminho.pt 2025-01-20
domain docs-pr.top 2025-01-20
domain tmcampos.pt 2025-01-20
hostname account-worda-ads.benephica.com 2025-01-20
hostname account-worda-ads.cacaobliss.pt 2025-01-20
hostname account.universitas-studio.es 2025-01-20
hostname accounts.google.lt1l.com 2025-01-20
hostname accounts.goosggles.com 2025-01-20
hostname accounts.lichseagame.com 2025-01-20
hostname accousnt-ads.tmcampos.pt 2025-01-20
hostname accousnt.benephica.pt 2025-01-20
hostname accousnt.hyluxcase.me 2025-01-20
hostname accousnt.whenin.pt 2025-01-20
hostname ads-google.io-es.com 2025-01-20
hostname ads1.google.lt1l.com 2025-01-20
hostname ads1.google.veef8f.com 2025-01-20
hostname as.vn-login.shop 2025-01-20
hostname vietnamworks.vn-login.shop 2025-01-20