Google has fallen victim to its own ad platform, allowing threat actors to create fake Google Authenticator ads that push the DeerStealer information-stealing malware.
In a new malvertising campaign found by Malwarebytes, threat actors created ads that display an advertisement for Google Authenticator when users search for the software in Google search.
What makes the ad more convincing is that it shows ‘google.com’ and “https://www.google.com” as the click URL, which clearly should not be allowed when a third party creates the advertisement.
We have seen this very effective URL cloaking strategy in past malvertising campaigns, including for KeePass, Arc browser, YouTube, and Amazon. Still, Google continues to fail to detect when these imposter ads are created.
Malwarebytes noted that the advertiser’s identity is verified by Google, showing another weakness in the ad platform that threat actors abuse.
When the download is executed, it will launch the DeerStealer information-stealing malware, which steals credentials, cookies, and other information stored in your web browser.
Users looking to download software are recommended to avoid clicking on promoted results on Google Search, use an ad blocker, or bookmark the URLs of software projects they typically use.
Before downloading a file, ensure that the URL you’re on corresponds to the project’s official domain. Also, always scan downloaded files with an up-to-date AV tool before executing.
Allowing showing different domains than the actual click target is wildly reckless and should be punishable.
“Oh but our poor advertisers want to use click tracking and it is too hard to set up on their main domain”. Oh boo hoo, I’m sure if it is important to them they will figure it out.
Probably they exploited the Google search redirect to have show google.com
Like this http://www.google.com/search?q=example&btnI
And because Google is a startup with limited resources they didn’t implement a check against that
Probably not. Google Ads explicitly allows mismatch between displayed domain and actual domain. This is literally a supported configuration with no tricks.
The link you sent gives me a “Redirect Notice” interstitial that mitigates this attack greatly.
I worked for Google Ads support for a while and even this dumbed down system completely stumped so many fucking people.
God I hate advertising and advertisers so much.
These useless fucking cunts wanted every feature imaginable, setup for free, with no effort of research done from them.
That job made me hate taxi drivers so much.
What do taxi drivers have to do with it?
They are probably in cahoots with the lemon stealing whores.
What do lemons have to do with it?
The lemon was stealing all the whores and used a taxi to get away with them.
Even then it should be easy to add an additional field in their ad profile. Like “provide a list of domains your ads will go to.”
And then set up some sort of domain authentication similar to let’s encrypt or SPF records.