PULSE NAME
Microsoft advertisers phished via malicious Google ads
WHITE AlienVault 2025-01-31 Modified: 2025-01-31
101
IOCs
HIGH VOLUME
Malicious actors are targeting Microsoft advertisers through fraudulent Google ads, aiming to steal login credentials for Microsoft's advertising platform. The campaign involves sophisticated techniques like cloaking, Cloudflare challenges, and redirection chains to evade detection. Phishing pages imitate the Microsoft Advertising platform, attempting to bypass 2-Step verification. The attack appears to be part of a larger, long-running campaign potentially affecting multiple advertising platforms. Users are advised to verify URLs carefully, use 2-Step verification wisely, monitor accounts regularly, and report suspicious ads. The article provides numerous indicators of compromise, including malicious domains associated with the campaign.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (101)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain 30yp.com 2025-01-31
domain aboutadvertselive.com 2025-01-31
domain aboutblngmicro.cloud 2025-01-31
domain account-microsoft.online 2025-01-31
domain account-microsoft.site 2025-01-31
domain account-mircrosoft-ads.com 2025-01-31
domain accounts-ads.site 2025-01-31
domain accounts-mircrosoft-ads.online 2025-01-31
domain acount-exchang.store 2025-01-31
domain admicrosoft.com 2025-01-31
domain admicrsdft.com 2025-01-31
domain ads-adversitingb.com 2025-01-31
domain ads-dsas.site 2025-01-31
domain ads-microsoft.click 2025-01-31
domain ads-microsoft.live 2025-01-31
domain ads-microsoft.online 2025-01-31
domain ads-microsoft.shop 2025-01-31
domain ads-microsoftz.online 2025-01-31
domain ads-miicrosoft.com 2025-01-31
domain ads-mlcrosft.com 2025-01-31
domain adslbing.com 2025-01-31
domain adsmicrosoft.shop 2025-01-31
domain adsverstoni.com 2025-01-31
domain advertiseliveonline.com 2025-01-31
domain advertising-bing.site 2025-01-31
domain advertising-mlcrosoft.org 2025-01-31
domain adverts2023.online 2025-01-31
domain advertsingsinginbing.com 2025-01-31
domain agency-wasabi.com 2025-01-31
domain bing-ads.com 2025-01-31
domain bitmax-us.com 2025-01-31
domain blngad.online 2025-01-31
domain blseaccount.cloud 2025-01-31
domain colneex-plalform.cloud 2025-01-31
domain connec-exchan.site 2025-01-31
domain digitechmedia.agency 2025-01-31
domain forteautomobile.com 2025-01-31
domain global-verifications.com 2025-01-31
domain global-verify.com 2025-01-31
domain homee-acount.com 2025-01-31
domain itlinks.com.cn 2025-01-31
domain krakeri-login.com 2025-01-31
domain lkub.com 2025-01-31
domain micrasofit.xyz 2025-01-31
domain microsoft-ads.website 2025-01-31
domain microsoftadss.com 2025-01-31
domain microsoftadversiting.cloud 2025-01-31
domain microsoftbingads.com 2025-01-31
domain mlcrosoft-bing-acces.click 2025-01-31
domain mlcrosoftadvertlsing.online 2025-01-31
domain mudinhox.site 2025-01-31
domain ndnet.shop 2025-01-31
domain phlyd.com 2025-01-31
domain portfoliokrakenus.com 2025-01-31
domain portfoliolkraken.com 2025-01-31
domain portfoliopro-us.com 2025-01-31
domain portfolioskranen.com 2025-01-31
domain portofolioprospots.com 2025-01-31
domain potfoliokeiolenen.com 2025-01-31
domain potfoliokelaken.com 2025-01-31
domain potfoliokelaneken.com 2025-01-31
domain potfoliokenaiken.com 2025-01-31
domain potfoliokenkren.com 2025-01-31
domain potfolioketonelen.com 2025-01-31
domain potfolioskaneken.com 2025-01-31
domain potfolioskenaken.com 2025-01-31
domain potfolioskraineken.com 2025-01-31
domain potfolioskranaken.com 2025-01-31
domain potfolioskraneken.com 2025-01-31
domain pro-digitalus.com 2025-01-31
domain prokrakenportfolio.com 2025-01-31
domain sig-in-mlcrosoft-advertisings.site 2025-01-31
domain uiiadvertise.online 2025-01-31
domain wvvw-microsoft.xyz 2025-01-31
domain www-bingads.com 2025-01-31
domain www-microsoftsads.com 2025-01-31
hostname account.colndcx-app.com 2025-01-31
hostname ads-microsoft.bewears.com 2025-01-31
hostname ads-microsoft.coachb-learning.com 2025-01-31
hostname ads-microsoft.lubrine.com.br 2025-01-31
hostname ads-mlcrosoft-com.blokchaln.com 2025-01-31
hostname ads.mcrosoftt.com 2025-01-31
hostname ads.microsoft.com.euroinvest.ge 2025-01-31
hostname ads.mlcr0soft.com 2025-01-31
hostname ads.mlcrosoft.com.ciree.com.br 2025-01-31
hostname ads.mlcrosoft.com.poezija.com.hr 2025-01-31
hostname ads.msicrosoft.com 2025-01-31
hostname ads.rnlcrosoft.com.euroinvest.ge 2025-01-31
hostname adsmicro.exchangefastex.cloud 2025-01-31
hostname bing.login-acount.me 2025-01-31
hostname bltrue.colnhouse-fr.us 2025-01-31
hostname login-adsmicrosoft.helpexellent.com 2025-01-31
hostname login.adsadvertising.online 2025-01-31
hostname login.microsofttclicks.live 2025-01-31
hostname microosft.accounts-ads.site 2025-01-31
hostname microsofyt.adversing-publicidade.pro 2025-01-31
hostname mictrest.mnws.ru 2025-01-31
hostname rnlcrosoft.smartlabor.it 2025-01-31
hostname www-v.userads.digital 2025-01-31
hostname www34.con-webs.com 2025-01-31
hostname www55.con-webs.com 2025-01-31