
Security researchers identified a widespread tech support scam operating through Google advertisements across numerous high-traffic websites including maps, weather, real estate, and sports platforms. Between August 31 and September 14, security firm Netskope observed users from 619 organizations encountering the malicious ads, though the firm’s blocking prevented actual compromises. The campaign utilized more than 250 separate Google Ads identifiers distributed across at least 284 legitimate publisher sites.
When clicked, the ads deliver sophisticated software that displays fake security warnings claiming device infection. The scam interface mimics genuine system warnings by disabling the browser address bar, filling the entire screen, disabling standard exit keys, and degrading browser performance through deliberate lag and sound effects. Messages instruct users not to restart their machines and to contact a phone number immediately. The deceptive design creates convincing pressure that compels users toward making the fraudulent call.
Approximately 62 percent of affected organizations were located in the United States, with Japan and Australia representing the second and third largest concentrations. Netskope’s visibility covers only a portion of internet activity, indicating actual exposure numbers substantially exceed observed cases. Users contacting the scam centers face demands for payment, requests for remote device access, or requests for personal information disclosure.
The scam’s technical sophistication enables evasion of standard security mechanisms. The warning software remains encrypted and only decrypts within browser memory, preventing many endpoint security tools and potentially Google’s ad filters from detection. The malicious code triggers only after mouse movement and displays differently depending on device operating system, targeting both Windows and macOS users separately.
Google stated it maintains zero tolerance for scams and indicated investigation into the identified campaigns. The company noted it blocked over 99 percent of policy-violating ads before serving in the previous year but did not specify whether these particular ads have been completely removed or explain how they bypassed initial detection. Users encountering such scams can typically escape by holding the escape key or using task manager functions to force-close the browser without restoring the previous session.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI