Google Search Ads Show Malware Again, This Time for Fake Authenticator(excerpt)
Multiple cybersecurity firms
reported this week that Google Search ads for what appears to be a Google authenticator actually lead to a download for "DeerStealer" malware. This authenticator was not made by Google, but by an unknown threat actor trying to swipe victims' personal information.
In this case, though, Google's ad settings helped make the fake ads look more convincing. The URL to the malware appeared as "https://www.google.com." Google's site also showed that the advertiser who posted the malware had their identity "verified by Google." The advertiser's location showed that they were based in the US, and the description snippet of the ad itself contained the text: "Official Website."
Unfortunately, this has
happened before, as Malwarebytes points out with the convincing—but fake and malicious—Amazon ads that surfaced on Google Search last year.
second article: (Great details, educational)Threat actor impersonates Google via fake ad for Authenticator (excerpt)
Conclusion
Threat actors have been abusing Google ads as a way to trick users into visiting phishing and malware sites. Since the whole premise of these attacks relies on social engineering, it is absolutely critical to properly distinguish real advertisers from fake ones.
As we saw in this case, some unknown individual was able to impersonate Google and successfully push malware disguised as a branded Google product as well.
We should note that Google Authenticator is a well-known and trusted multi factor authentication tool, so there is some irony in potential victims getting compromised while trying to improve their security posture. We recommend avoiding clicking on ads to download any kind of software and instead visiting the official repositories directly.
Malwarebytes blocks access to the fake Authenticator website, and we detect the payload as Spyware.DeerStealer.
-------------- (end excerpt)-------------
Lessons to be learned: Do not trust any ads are properly vetted; as bad actors are creative Always go to the source for any download Keep your security Software up to date