Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

by | Oct 7, 2026 | Technology

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Security researchers identified a widespread tech support scam distributed through Google advertisements across numerous high-traffic websites including maps, weather, real estate, document hosting, and sports platforms. The malicious ads were engineered to freeze computer screens on both Windows and Mac devices while displaying urgent messages instructing users to contact a fake support center.

From August 31 to September 14, security firm Netskope detected users from 619 customer organizations encountering the fraudulent ads. Approximately 62 percent of affected organizations were located in the United States, with Japan and Australia representing the second and third largest concentrations. The firm tracked over 250 distinct Google Ads campaign identifiers across at least 284 legitimate publisher websites. Netskope’s security infrastructure prevented actual compromises, though the total number of exposed users across the broader internet likely substantially exceeds the observed figures.

The scam employs sophisticated technical methods to appear legitimate. The malware obscures the browser address bar, disables keyboard shortcuts normally used to exit windows, and artificially degrades browser performance through lag and sound effects. The fake warning messages fill the entire screen, and attempts to close the browser cause the scam interface to refresh. The underlying software is encrypted and only decrypts within browser memory, making detection by security software significantly more difficult. Device-specific versions target Windows and macOS users separately.

Google stated it maintains a zero-tolerance policy toward scams and indicated it was investigating the reported campaigns. The company claimed to block over 99 percent of policy-violating advertisements before distribution, though it did not specify why this particular campaign escaped detection or confirm complete removal from its platform.

Security experts noted that despite appearing locked, affected devices retain functional escape routes. Users can typically press and hold the escape key for several seconds to exit full-screen mode, or utilize system task managers to force-close browsers. Legitimate technology companies never request phone calls from users experiencing security issues, and anyone receiving such communications should disregard them entirely.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI