Phishing links and malware are threats that every online user is familiar with, but sophisticated attacks can catch even the most security-conscious users off guard. There’s nothing more confusing than imitating Google on its own platform.

Notice! Unscrupulous people are using Google search ads to impersonate Google
In a recent malvertising campaign, hackers purchased “sponsored” ad sections in Google search to promote fake Google Authenticator download links. Anyone searching for the keyword “Google Authenticator” on Google will likely see this ad, which at first glance looks completely legitimate and appears to use the official URL of “www.google.com.”

When you click on the ad, you’ll see a fake Google Authenticator website at “www.chromeweb-authenticators.com.” Pressing the highlighted download button on the website immediately triggers the download of “Authenticator.exe”, an executable file hosted on GitHub and signed by the developer. The origin of the executable, coupled with its verified nature, means it will not be reviewed by the victim’s web browser or the Windows Defender antivirus service.

The executable is actually an information-stealing malware called DeerStealer. After Malwarebytes discovered signs of malicious advertising activity, it immediately contacted Google, and Google removed the offending ads from its platform. What’s going on? In fact, it is very simple. Google accidentally sold the advertising column to unscrupulous people. according to Bleeping Computer According to the report, Google said the hackers bypassed human and automated review systems by using text manipulation and disguise to display the website differently than what regular users would see.

Image source: Malwarebytes
Most people know not to click on random ads, but the problem, of course, is that the “sponsored” fields in Google search results aren’t ads in the traditional sense. It is designed to be relevant to the topic you are searching for, and is often intended to be used by legitimate companies to appear more prominently in Google searches. Even if you realize that a search result is a sponsored ad, it may be what you were looking for. In this case, the user searched for Google’s own product on Google, then saw an ad for the product and clicked on it, thereby being scammed under completely reasonable actions.

This isn’t the first time Google’s ad platform has been used for malware distribution or phishing. In fact, fighting malware has been a decades-long struggle for Google and will inevitably continue in the future. We recommend that you avoid clicking on “sponsored” results in Google searches, although this may be easier said than done as it can be difficult to distinguish these ads from normal search results, but try!
Source: KOCPC Chinese