Hackers are using fake ads on Google search to promote phishing sites that steal advertisers' credentials to access Google Ads accounts.

Attackers are displaying ads on Google Search that mimic Google Ads. They display them as sponsored results and redirect potential victims to fake login pages hosted on Google Sites, but which look like the official Google Ads homepage. Users are prompted to log in to their accounts .
Google Sites is used to host phishing pages because it allows hackers to hide fake ads. The URL (sites.google.com) matches the Google Ads root domain for complete impersonation.
See also: Hackers abuse Google Ads to spread Fakebat malware
“Indeed, you cannot display a URL in an ad unless the landing page (final URL) corresponds to the same domain name. While this is a rule intended to protect against abuse and impersonation, it can be easily circumvented,” said Jérôme Segura, Senior Research Director at Malwarebytes.
“Looking again at the ad and the Google Sites page, we see that this malicious ad does not strictly violate the rule, as sites.google.com uses the same root domain ads.google.com. In other words, it is allowed to display this URL in the ad, making it indistinguishable from the same ad served by Google LLC.“.

This particular malicious campaign includes several stages:
- The victim enters their Google account details on the phishing page.
- The phishing kit collects identification data, cookies, and credentials.
- The victim may receive an email indicating a link from an unusual location (Brazil).
- If the victim continues, a new administrator will be added to the Google Ads account via a different Gmail address.
- The attacker can lock victims out of their Google Ads accounts.
See also: iMessage: Hackers trick you into disabling phishing protection
At least three hacking groups appear to be behind these attacks. Malwarebytes Labs, which detected the malicious Google Ads campaign, believes the attackers are aiming to sell the stolen accounts on hacking forums. They may also use some to carry out future attacks.
This is a campaign that reaches to the core of Google's business and likely affects thousands of its customers worldwide. New incidents are being discovered all the time.
“It is very likely that individuals and businesses running advertising campaigns are not using an ad blocker, making them even more susceptible to these phishing schemes.“.
Stolen Google Ads accounts are often targeted by hackers because they help them in other attacks and fraud.
See also: Phishing campaign steals PayPal accounts
“We explicitly prohibit ads that aim to trick people into stealing their information or defrauding them. Our teams are actively investigating this issue and working quickly to address it,” Google told BleepingComputer.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Phishing protection
- Protecting devices with antivirus
- Regular software updates
- Using a unique password for each of your online accounts
- Multi-factor authentication application
- Backup
- Informing staff about new threats and training with test phishing attacks
- Monitoring and protecting endpoints
- Restricting access to important systems
- Network segmentation
Source: www.bleepingcomputer.com
