
Security researchers have identified a sophisticated tech support scam being distributed through Google advertisements across numerous high-traffic websites, including maps, weather, real estate, document hosting, and sports sites. The malicious ads display warnings that appear to freeze both Windows and Mac computer screens, instructing users to contact a fraudulent call center for assistance. According to Netskope, a security firm that tracked the campaign, users from 619 customer organizations clicked on the ads between August 31 and September 14, though none were successfully scammed due to Netskope’s blocking measures.
Approximately 62 percent of affected organizations were located in the United States, with Japan and Australia representing the second and third largest concentrations of exposure. Netskope identified more than 250 Google Ads campaign IDs operating across at least 284 legitimate publisher websites. The firm estimates that the actual number of exposed users is significantly higher given the limited visibility available to security companies into overall internet activity.
The scam operates by creating a convincing illusion of a compromised device. The software toolkit used disables the browser address bar, occupies the entire screen, disables keyboard shortcuts like the escape key, and degrades browser performance while playing alarm sounds. The fake warning messages urge users not to restart their machines and to call the provided number immediately. Notably, the malicious software only activates after mouse movement and operates in encrypted form within browser memory, making detection by security software and Google’s ad filters more difficult.
Google stated it has zero tolerance for scams and is actively investigating the campaigns, though the company did not explain how the ads evaded its security systems or confirm complete removal from its platform. The company noted it blocked over 99 percent of violating ads in the previous year before they were served to users. Security experts advise that devices are not actually locked despite disabled keyboard functions, and users can typically escape the scam by holding the escape key for several seconds or using system shortcuts like Control-Shift-Escape on Windows or Command-Option-Escape on Mac to force close the browser.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI