Chinese-speaking users are being targeted by a new malvertising campaign, where malicious ads appear on Google (Google ads) and promote messaging apps, such as Telegram.

Malwarebytes' Jérôme Segura said that attackers are abusing Google advertiser accounts to create malicious ads that lead to pages to download Remote Administration Trojan (RAT).
“Such programs give the attacker full control of the victim's machine and the ability to install additional malware“.
See also: MS Drainer: Crypto drainer distributed through ads on Google and X
The malvertising campaign, codenamed FakeAPP, follows previous attacks targeting Hong Kong users searching for messaging apps like WhatsApp and Telegram, which took place in late October 2023.
The latest campaign adds messaging app LINE to the list of apps that were previously available. The malicious ads redirect users to fake websites hosted on Google Docs or Google Sites.
Google's infrastructure is used to embed links to other websites under the control of attackers and deliver malicious installation files that ultimately deploy trojans such as PlugX and Gh0st RAT.
See also: X users frustrated by constant stream of malicious crypto ads
According to Malwarebytes, the malicious ads came from two advertiser accounts named Interactive Communication Team Limited and Ringier Media Nigeria Limited , which are based in Nigeria.
Segura also says that attackers are placing more emphasis on quantity rather than quality, constantly pushing new payloads and infrastructure as command-and-control.

How can users protect themselves from malicious ads?
To protect themselves, users should be careful about the ads they click on on Google. If an ad looks suspicious, promotes an unknown app, or doesn't look official, it's best to avoid clicking.
They should also always check the destination URL before clicking on an ad. If the website is not trustworthy or well-known, it is better not to proceed.
See also: Fake Google Ads mimic Kinsta pages
Additionally, it is important to keep their applications and operating system up to date. Updates often include security fixes that can help protect against such attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, using reliable security software can help identify and prevent the installation of malware.
Source: thehackernews.com
