Concise Cyber

Subscribe below for free to get these delivered straight to your inbox

Advertisements
MasquerAds Campaign: Fake Google & Bing Ads Lure 500,000+ into Malware Trap
Advertisements

Security researchers have uncovered a massive malvertising campaign that successfully victimized over 500,000 people. The operation, dubbed MasquerAds by the Guardio Labs team that discovered it, leveraged fraudulent advertisements on major search engines, including Google and Microsoft Bing, to distribute information-stealing malware.

The threat actors behind the campaign targeted users searching for popular software tools. Victims were tricked into downloading malicious installers that ultimately compromised their personal and financial data.

How the Malvertising Scheme Operated

The MasquerAds campaign relied on placing malicious ads at the top of search engine results for popular software queries. Brands impersonated in the scheme included Grammarly, Afterburner, Slack, OBS, Notion, Dashlane, and Malwarebytes. When a user clicked on one of these fraudulent ads, they were redirected to a meticulously crafted lookalike phishing website designed to appear legitimate.

Believing they were on the official download page, victims would then download a file disguised as a software installer. This file was actually a malicious loader. The campaign was reported to have a high click-through rate of 10-20% on its malicious ads during one particularly active weekend.

Deployment of Info-Stealing Malware

Once the user executed the fake installer, the loader would deploy an info-stealer malware onto the victim’s computer. This type of malware is designed to exfiltrate sensitive information directly from web browsers. The primary goal of the info-stealer was to harvest stored login credentials, financial details, and other personal data from the compromised device. Following the report from Guardio Labs, the malicious infrastructure associated with the campaign was taken down.

All articles are written here with the help of AI on the basis of openly available information which cannot be independently verified. We do strive to quote the relevant sources.The intent is only to summarise what is already reported in public forum in our own wordswith no intention to plagarise or copy other person’s work.The publisher has no intent to defame or cause offence to anyone, any person or any organisation at any moment.The publisher assumes no responsibility for any damage or loss caused by making decisions on the basis of whatever is published on cyberconcise.com.You’re advised to do your own checks and balances before making any decision, and owners and publishers at cyberconcise.com cannot be held accountable for its resulting ramifications.If you have any objections, concerns or point out anything factually incorrect, please reach out using the form on https://concisecyber.com/about/

Discover more from Concise Cyber

Subscribe now to keep reading and get access to the full archive.

Continue reading