HomeYoutubeFake Google Authenticator sites install DeerStealer malware

Fake Google Authenticator sites install DeerStealer malware

Google has fallen victim to its own ad platform, as malicious actors create fake Google Authenticator ads, which push DeerStealer malware.

See also: Chinese hackers target Japanese companies with LODEINFO and NOOPDOOR Malware

For years, malicious advertising campaigns (malvertising) have targeted the Google search platform, where malicious actors place ads to mimic well-known software sites that install malware on visitors’ devices. To make matters worse, hackers have been able to create Google search ads that display legitimate domains, which adds a sense of trust to the ad.

Google Authenticator DeerStealer malware

In a new malvertising spotted by Malwarebytes, threat actors created ads for Google Authenticator when users search for the software in Google search, in order to push DeerStealer malware. What makes the ad more convincing is that it displays “google.com” and “https://www.google.com” as the URL, which clearly shouldn’t be allowed when a third party creates the ad.

We've seen this very effective URL hiding strategy in previous malvertising campaigns, including KeePass, Arc browser, YouTube , and Amazon. However, Google still fails to detect when these fake ads are being created.

Malwarebytes noted that the advertiser's identity is verified by Google, pointing to another weakness of the advertising platform that threat actors are abusing.

Google told BleepingComputer that it had blocked the fake advertiser reported by Malwarebytes.

See also: SMS stealer malware campaign infects Android devices

When asked how malicious actors can create ads impersonating legitimate companies, Google said they avoid detection by creating thousands of accounts at once and using text manipulation and obfuscation to show reviewers and automated systems different websites than what a regular visitor would see.

However, the company is increasing the scale of its automated systems and human reviewers to help identify and remove these malicious campaigns. These efforts have allowed them to remove 3.4 billion ads, limit over 5.7 billion ads, and suspend over 5.6 million accounts in 2023.

Fake Google Authenticator sites install DeerStealer malware

How DeerStealer malware is installed via Google Authenticator

When a user clicks on the fake Google Authenticator ads, they are taken through a series of redirects to the landing page at “chromeweb-authenticators.com,” which impersonates a genuine Google portal. Clicking on the “Download Authenticator” button triggers the download of a signed executable file named “Authenticator.exe” hosted on GitHub.

The GitHub repository hosting the malware is called “authgg” and the repo owners are called “authe-gogle.” Both sound like names related to the campaign theme.

The valid signature gives the file credibility in Windows, potentially bypassing security solutions and allowing it to run on the victim's device without warnings.

When the download is executed, it will launch the DeerStealer malware, which steals credentials, cookies, and other information stored in your browser.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Users who want to download software are advised to avoid clicking on promoted results in Google Search, use an ad blocker, or bookmark the URLs of software projects they commonly use.

See also: Hackers Target Polish Businesses with Agent Tesla and Formbook Malware

Before downloading a file, make sure the URL you are on corresponds to the official domain of the project. Also, always scan downloaded files with an up-to-date AV tool before executing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS