A cloud-based tech-support scam is leveraging Google Ads to lure users into fake security warnings that mimic browser takeover threats This article explores scam leveraging google. . Threat Labs reveals that attackers aim to trick victims into calling a bogus support number, where they might be pressured to pay for fake assistance, grant remote access, or share sensitive information.
The researchers did not indicate that the page installs malware; the risk lies in what a victim might be persuaded to do after calling. After clicking an ad, the victim encounters a page with a loading spinner and two buttons, “Cancel” and “Continue.” It then appears to be an ordinary online store called ShopEase.
The scam kit’s hidden code activates behind a harmless-looking page, waiting for a mouse movement before executing its malicious code. The page also hides the cursor, blocks exit keys through the browser's keyboard-lock API, emits alert sounds, and deliberately makes the browser lag. Netskope found that most visits were linked to paid Google ads, including parameters like gclid, gad_source, and gad_campaignid.
Researchers identified more than 250 Google Ads campaign IDs associated with ads on at least 284 legitimate publisher sites. Join 16,000+ SOC teams using ANY.RUN to enhance threat investigations and minimize manual workload. Explore for your team.










