Malicious Google Ads Freeze Windows and Mac Screens in Sophisticated Tech Support Scam
Researchers have discovered a sophisticated tech support scam delivered through Google Ads that freezes Windows and Mac screens and urges users to call a fake support center.
The malicious ads appeared across the web, including on high-traffic maps, weather, real estate, document-hosting, and sports websites. Users who called the displayed number were asked to pay a large fee, grant remote access to their device, or provide personal information.
Between August 31 and September 14, security firm Netskope observed users at 619 customer organizations clicking the malicious ads. Netskope blocked the content, so none of the users it tracked were actually scammed.
Approximately 62% of the affected organizations were based in the United States, followed by Japan and Australia. The total number of people exposed to the ads—including potential victims—could be much higher because Netskope captures only a small portion of internet activity.
Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher websites.
How the fake security alert works
“For victims, this tradecraft turns regular ad clicks into browsers that appear to capture bogus security alerts,” Netskope said in its report.
The scam uses browser-based “lockers” that fill the screen, hide the cursor, disable the usual exit key, and slow down the browser. These tactics create the impression that the computer is broken and pressure users to call the phone number shown on the screen.
Although nothing on the computer is actually locked, Netskope said the fake alerts are convincing enough to lure people into the scam.
Why people fall for tech support scams
People who fall for these scams are often ridiculed, but that criticism overlooks the large number of internet users with little or no understanding of how computers and the web work. Limited technical knowledge, the pressure to complete tasks quickly, and the increasing difficulty of navigating the web can make users especially vulnerable.
Some potential victims may even be friends or family members who do not know enough about technology to recognize that an alarming security warning is fake.
Source: arstechnica.com


