Google Ads Users Fall Victim to Sneaky Phishing Scheme
A new phishing campaign is targeting Google Ads users by tricking them into entering their login details on fraudulent websites. The attackers use Google Ads to display fake ads that look like legitimate Google login pages. When users click on these ads, they are redirected to fake sites designed to steal their login credentials and two-factor authentication codes.
Cybersecurity experts from Malwarebytes revealed that the goal of the attack is to hijack Google Ads accounts, using stolen credentials to push fake ads and further spread the scam. The fraudsters cleverly exploit a loophole in Google’s system, allowing them to display misleading URLs while hiding the true destination of the ads. This makes it harder for users and even Google to spot the fraud until it’s too late.
The campaign is believed to be run by a group of Portuguese-speaking attackers, likely based in Brazil, and has been active since November 2024. As these attacks grow more sophisticated, businesses and users must be extra cautious when clicking on ads, especially those that seem too good to be true.
Source: https://thehackernews.com/2025/01/google-ads-users-targeted-in.html