
Security researchers have identified a widespread tech support scam campaign distributed through Google advertisements across numerous high-traffic websites. The malicious ads appeared on maps, weather, real estate, document hosting, and sports sites, delivering deceptive security warnings designed to freeze computer screens and prompt users to contact fraudulent call centers.
From August 31 to September 14, security firm Netskope observed users from 619 customer organizations encountering the malicious ads, with approximately 62 percent of affected organizations based in the US, followed by Japan and Australia. The firm tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. Because Netskope’s visibility represents only a fraction of total internet activity, the actual number of people exposed to the campaign is substantially higher. Netskope’s security measures prevented users at its customer organizations from being scammed, though the true victim count remains unknown.
The scam leverages sophisticated technical tactics to appear convincing. When users click the ads, their browsers display full-screen fake security warnings accompanied by messages instructing them not to restart their machines and to call a specified number immediately. The warning software disables common keyboard shortcuts, degrades browser performance, plays sounds, and causes page lag to simulate genuine system compromise. The software only appears after mouse movement and operates encrypted in browser memory, techniques designed to evade security detection systems. The warnings are customized for both Windows and macOS devices.
Google stated it maintains zero tolerance for scams and is actively investigating the campaigns, promising action against violating accounts. The company reported blocking over 99 percent of violating ads before serving them in the prior year but did not explain why these particular campaigns escaped detection or confirm complete removal from its platform.
Devices subjected to the scam are not actually locked despite appearing frozen. Users can typically exit the fake warning by holding the escape key for several seconds on either Windows or macOS, or by using task manager commands to force close the browser. Experts caution that legitimate companies never request phone calls in response to security infections and advise against contacting any numbers displayed on such warnings.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI