Fake "locked computer" alerts in Google Ads are tricking users into calling tech-support scammers
The goal was not to install malware or lock the computer. It was to create enough confusion to get people to call the number on the screen. Callers were then pressured to pay for bogus support, hand over personal information or allow someone to remotely access their device. Read Entire Article
A malicious Google Ads campaign has been spreading fake security warnings to Windows and Mac users, tricking them into calling fraudulent technical-support numbers. These deceptive ads appeared on reputable, high-traffic websites, including popular sites like maps, weather, real estate, sports, and document-hosting pages. Upon clicking the ads, users were bombarded with full-screen warnings, making it seem as though their devices had been compromised or disabled.
The primary objective was not to install malware or lock the computer, but rather to create enough confusion to persuade people to call the displayed number. Unscrupulous callers pressured victims into paying for fake support, sharing personal information, or granting remote access to their devices.
Security firm Netskope discovered the campaign between August 31 and September 14, tracking user interactions with the fraudulent pages from 619 customer organizations. Although Netskope's security tools prevented many users from being scammed, the company believes the attack may have reached a far greater audience. More than 62% of affected organizations were located in the United States, followed by Japan and Australia.
Over 250 Google Ads campaign IDs and more than 284 legitimate publisher sites were found to be involved in this scheme.
What set this campaign apart was its ability to mimic a true system failure, convincing users that their devices were genuinely locked. The fraudulent page took over the browser, hiding the address bar and cursor, and interfering with keyboard shortcuts, making it challenging to exit full-screen mode. The browser also experienced slow performance and played sounds, further exacerbating the illusion of a system failure.
Netskope noted that the fraudulent warnings were tailored for both Windows and macOS, and the page remained hidden until mouse movement was detected.
The malicious code was encrypted and only decrypted in browser memory shortly before the warning was displayed, making it difficult for endpoint security tools and ad-scanning systems to detect. The warning pages were designed to hinder users from simply closing the browser, requiring them to press the Escape key, hold it for several seconds, or use the Task Manager on Windows or the Force Quit menu on Macs to regain control.
Google has stated that it is actively investigating the campaign and will take appropriate action against any accounts violating its policies. The company has blocked over 99% of policy-violating ads before they are served, but this particular campaign managed to slip through the cracks through clever browser manipulation.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.