A Fake Security Locker, Delivered by Google Ads

A Fake Security Locker, Delivered by Google Ads
Netskope Threat Labs tracked a cloud-hosted tech-support-scam kit that uses fake loading screens, browser full-screen tricks, and runtime decryption to display bogus Microsoft Defender or Apple alerts and push victims to call a scam support number. The campaign was distributed through paid Google Ads, affected at least 619 organizations, and used anti-analysis tradecraft to hide its hidden C2 and encrypted payloads. #Netskope #GoogleAds #MicrosoftDefender #Apple #ShopEase

Keypoints

  • The scam begins with a Google ad click that leads to a fake loading screen and then an ordinary-looking storefront branded “ShopEase.”
  • The kit uses a mouse-movement gate to block automated analysis before revealing its hidden logic.
  • It decrypts a hidden C2 address and then fetches an encrypted payload tailored to Windows or macOS victims.
  • The final browser locker is assembled in memory, avoiding delivery of an inspectable malicious file over the network.
  • On Windows, the scam impersonates Microsoft Defender; on macOS, it is reskinned as an Apple-themed warning.
  • The page forces full-screen mode, hides the cursor, uses keyboard-lock behavior, and slows the browser to pressure victims into calling.
  • Over a two-week period, the campaign affected at least 619 organizations, with most traffic arriving through paid Google Ads.

MITRE Techniques

  • [T1056.002 ] GUI Input Capture: GUI Input Capture – The kit waits for mouse movement to bypass automated scanners and only proceeds after a real cursor event (‘it waits for a single mouse movement’).
  • [T1027 ] Obfuscated Files or Information – The kit hides its C2 and payload by decrypting them only at runtime (‘it decrypts a hidden string to recover the live C2 address’ and ‘decrypts that too’).
  • [T1071.001 ] Web Protocols – The payload is retrieved from a cloud-hosted C2 over the web (‘it fetches the actual locker from that C2’).
  • [T1204.001 ] Malicious Link – The victim is funneled into the scam via a Google ad click (‘Most traffic comes through Google Ads’).
  • [T1548.002 ] Bypass User Account Control – Not mentioned.
  • [T1055 ] Process Injection – Not mentioned.
  • [T1082 ] System Information Discovery – The payload is tailored based on whether the victim is on Windows or a Mac (‘choosing a Windows or macOS payload’).
  • [T1562.001 ] Impair Defenses – The locker degrades browser behavior and suppresses normal exit paths (‘hides the mouse cursor’ and ‘calls the browser’s keyboard-lock API to swallow the Escape key’).
  • [T1491.001 ] Internal Defacement: Malicious Content Injection – The scam replaces the page with fake security alerts and lockout screens (‘assemble the fake alert within browser memory’ and ‘a black lockout screen … flashes over everything’).
  • [T1205.001 ] Traffic Signaling – The ad-click tracking parameters indicate delivery through paid ad infrastructure (‘gclid, gad_source, and gad_campaignid’).

Indicators of Compromise

  • [Domain / URL ] paid-ad redirect and campaign traffic – googleads.g.doubleclick.net, cloud-hosted URLs, and other scam-hosting URLs
  • [Tracking parameters ] Google Ads click attribution – gclid, gad_source, and gad_campaignid
  • [Brand / decoy name ] fake storefront used in the lure – ShopEase
  • [Malware / kit name ] referenced related threat – CypherLoc
  • [Detection name ] Netskope inline detection – Generic.Phishing Tech Support Scam Kit Detected


Read more: https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads