PULSE NAME
Microsoft advertisers phished via malicious Google ads
WHITE AlienVault 2025-01-31 Modified: 2025-01-31
101
IOCs
HIGH VOLUME
Malicious actors are targeting Microsoft advertisers through fraudulent Google ads, aiming to steal login credentials for Microsoft's advertising platform. The campaign involves sophisticated techniques like cloaking, Cloudflare challenges, and redirection chains to evade detection. Phishing pages imitate the Microsoft Advertising platform, attempting to bypass 2-Step verification. The attack appears to be part of a larger, long-running campaign potentially affecting multiple advertising platforms. Users are advised to verify URLs carefully, use 2-Step verification wisely, monitor accounts regularly, and report suspicious ads. The article provides numerous indicators of compromise, including malicious domains associated with the campaign.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (25 / 101 total)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname account.colndcx-app.com 2025-01-31
hostname ads-microsoft.bewears.com 2025-01-31
hostname ads-microsoft.coachb-learning.com 2025-01-31
hostname ads-microsoft.lubrine.com.br 2025-01-31
hostname ads-mlcrosoft-com.blokchaln.com 2025-01-31
hostname ads.mcrosoftt.com 2025-01-31
hostname ads.microsoft.com.euroinvest.ge 2025-01-31
hostname ads.mlcr0soft.com 2025-01-31
hostname ads.mlcrosoft.com.ciree.com.br 2025-01-31
hostname ads.mlcrosoft.com.poezija.com.hr 2025-01-31
hostname ads.msicrosoft.com 2025-01-31
hostname ads.rnlcrosoft.com.euroinvest.ge 2025-01-31
hostname adsmicro.exchangefastex.cloud 2025-01-31
hostname bing.login-acount.me 2025-01-31
hostname bltrue.colnhouse-fr.us 2025-01-31
hostname login-adsmicrosoft.helpexellent.com 2025-01-31
hostname login.adsadvertising.online 2025-01-31
hostname login.microsofttclicks.live 2025-01-31
hostname microosft.accounts-ads.site 2025-01-31
hostname microsofyt.adversing-publicidade.pro 2025-01-31
hostname mictrest.mnws.ru 2025-01-31
hostname rnlcrosoft.smartlabor.it 2025-01-31
hostname www-v.userads.digital 2025-01-31
hostname www34.con-webs.com 2025-01-31
hostname www55.con-webs.com 2025-01-31