ThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases. The campaign sent victims through Google Cloud Storage and Google Sites, then used a fake device-verification flow to collect wallet credentials. #Ledger #GoogleAds #GoogleCloudStorage #Vercel #GoogleSites
Keypoints
- ThreatLabz identified a phishing campaign in August 2026 that targeted Ledger hardware wallet users through fraudulent Google ads.
- The ads appeared under a Google-verified advertiser profile and used Ledger-related search terms to lure victims.
- Victims were redirected from Google Cloud Storage to changing Vercel domains and then to a Google Sites page with the phishing content embedded in an iframe.
- The Vercel redirect domains appeared to change every 15-20 minutes, likely to hinder detection.
- The phishing page mimicked Ledger’s interface, offered fake downloads for multiple platforms, and used a device-verification flow to trick users into entering their secret recovery phrases.
- Submitted recovery phrases were sent to attacker-controlled Vercel endpoints, and the page used hCaptcha and analytics scripts during the process.
- Zscaler detects this activity as HTML.Phish.Ledger.
MITRE Techniques
- [T1583.001 ] Acquire Infrastructure: Domains – Attackers used changing Vercel-hosted domains and Google-hosted pages to support the redirect chain and phishing delivery (‘the Vercel domain … appeared to change approximately every 15-20 minutes’; ‘redirected them to a Vercel-hosted page’).
- [T1584.001 ] Compromise Infrastructure: Domains – The campaign appears to have used a long-standing verified advertiser account, possibly compromised to run malicious Google ads (‘The threat actor may have compromised the account to run the campaign’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The phishing flow relied on web redirects across Google Cloud Storage, Vercel, and Google Sites to deliver the fake Ledger page (‘Clicking the malicious ad took users to a Google Cloud Storage URL, which redirected them …’).
- [T1566.002 ] Phishing: Spearphishing Link – Fraudulent Google ads led victims to a phishing page impersonating Ledger and prompting recovery-phrase entry (‘malicious sponsored ads’; ‘asked the user to enter their secret recovery phrase’).
- [T1185 ] Browser Session Hijacking – Not directly mentioned as session hijacking; however, the page monitored user interaction and used a fake verification flow to capture wallet access information (‘monitoring user interactions like keypresses, touches, and mouse movements’).
- [T1056.001 ] Input Capture: Keylogging – The page tracked keystrokes and captured typed recovery phrases through input fields (‘monitored user interactions like keypresses’; ‘asked the user to enter their secret recovery phrase’).
- [T1119 ] Automated Collection – The phishing page automatically sent entered recovery phrases to an attacker-controlled endpoint and used autocomplete for BIP-39 words (‘The phishing page retrieves the 2,048-word BIP-39 English wordlist’; ‘sent it to an attacker-controlled Vercel domain’).
Indicators of Compromise
- [GCS Bucket URL ] Google Cloud Storage redirect infrastructure used in the campaign – storage[.]googleapis[.]com/apf-leg-ad-23798, storage[.]googleapis[.]com/ledg-leg1-79230, and other 2 items
- [Google Sites URL ] Final phishing landing pages impersonating Ledger – sites[.]google[.]com/view/start-ledger-wallet, sites[.]google[.]com/view/apps-ledger-wallet, and other 1 item
- [Vercel Domains ] Attacker-controlled redirect and collection endpoints – soyyoo-cwpc5n0e[.]vercel[.]app, rpc-gbz5[.]vercel[.]app, and other 3 items
- [Threat name ] Zscaler detection label for this campaign – HTML.Phish.Ledger
- [File name / script ] Analytics and wordlist resources used by the phishing page – beacon.min.js, api/bip39-english.txt
Read more: https://www.zscaler.com/blogs/security-research/threat-actors-use-google-ads-target-ledger-users