
Google ads delivered convincing scareware to Windows and Mac users, Netskope finds
Security researchers at Netskope have uncovered a malvertising campaign that used Google ads to freeze Windows and Mac screens with fake infection warnings and pushed users to call a bogus support line.
Security researchers at Netskope have uncovered a malvertising campaign that used Google ads to deliver a tech support scam to Windows and Mac users, Ars Technica reported on September 25. The ads froze screens with fake infection warnings and urged victims to call a bogus call center.
The ads ran on high-traffic maps, weather, real-estate, document-hosting and sports sites. People who called the displayed number were pressed to pay hefty fees, grant remote access to their devices or share personal information.
619 organizations clicked the malicious ads
From August 31 to September 14, Netskope observed users from 619 customer organizations clicking on the malicious ads. None of them were actually scammed, because the firm blocked the malicious content. Roughly 62 percent of the affected organizations were based in the United States, with Japan and Australia ranking second and third.
Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. Because the firm sees only a tiny sliver of internet traffic, the real number of exposed users is likely much higher.
A fake screen that mimicked a real infection
Clicks led to a cloud-hosted page that showed a loading spinner and then a harmless-looking online store. The kit waited for a mouse movement before acting, a trick that stalls automated scanners. It then decrypted a hidden server address, pulled an encrypted payload tailored to Windows or macOS and assembled the fake warning in browser memory, so no inspectable file crossed the network.
The locker hid the address bar, filled the entire screen, disabled the escape key and many other keys, and slowed the browser with sounds and lags. On Windows the page imitated a Microsoft Defender scan; on Mac it used Apple-styled alerts. Those techniques may have helped the campaign slip past endpoint security tools and possibly Google's own ad filters.
Google's response and how to escape the trap
Google did not say why its scanners missed the campaign or whether the ads have been fully removed. "We have zero tolerance for scams," the company said in a statement, adding that it is investigating the campaigns and will act against accounts that violate its policies. Google says it blocked over 99 percent of violating ads before they were served last year.
Nothing on a victim's computer is actually locked. In most cases, holding the escape key for several seconds forces the browser out of full screen and releases the keyboard lock, after which the tab can be closed. Windows users can also open Task Manager with control-shift-escape; on a Mac, Force Quit with cmd-option-escape. Netskope and Ars Technica stress that no legitimate company will ever advise users to call a phone number because of an infection.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.