Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Between August 31 and September 14, Netskope recorded 619 distinct customer organizations whose employees clicked on malicious Google ads that turned the browser into a full‑screen “locker.” The ad overlay concealed the cursor, disabled typical exit keys and simulated a system crash, then displayed a toll‑free number promising a quick fix. Although Netskope’s filters stopped the payload from executing, the campaign spanned more than 250 Google Ads IDs and appeared on at least 284 legitimate publisher sites ranging from maps and weather services to real‑estate and sports pages. Roughly 62 % of the impacted firms were in the United States, with Japan and Australia rounding out the top three countries.
The episode illustrates how sophisticated ad‑fraud actors are weaponizing Google’s own ad network to deliver classic tech‑support scams that have traditionally relied on cold‑calling or pop‑ups. By embedding the lock‑screen effect within an ad, the perpetrators bypass many browser‑based security prompts, exploiting the trust users place in familiar domains. This tactic aligns with a broader shift toward “malvertising,” where attackers purchase legitimate ad inventory to reach a wide audience while remaining under the radar of traditional anti‑malware tools. Google’s vast ecosystem, while enabling small businesses to advertise, also provides a low‑cost distribution channel for these scams, raising questions about the adequacy of its vetting processes.
Looking ahead, enterprises should assume that ad‑based threats can reach even well‑secured networks, especially when users lack technical fluency. Security platforms need deeper visibility into ad‑traffic and real‑time blocking capabilities similar to Netskope’s, while Google must tighten its campaign‑approval workflows and accelerate removal of suspect IDs. End‑user education remains critical: the visual lock‑screen can appear convincing, but the absence of actual OS‑level lock indicators and the presence of a phone number are tell‑tale signs. Monitoring for sudden spikes in ad‑clicks to unknown numbers could serve as an early warning for similar campaigns.
Key Takeaways
Netskope intercepted a Google‑Ads‑driven tech‑support scam that froze browsers on both Windows and macOS for 619 organizations in a two‑week window.
The operation leveraged over 250 ad campaign IDs across 284 reputable publisher sites, demonstrating the scale at which malvertising can infiltrate mainstream web content.
The majority of affected firms were U.S.‑based, highlighting that even markets with strong security awareness are vulnerable to deceptive ad formats.
Enterprises should augment browser security with ad‑traffic inspection and reinforce user training to recognize fake lock‑screen warnings.
About the Source
This analysis is based on reporting by Ars Technica. Here is a short excerpt for context:
Ads appearing all over the Internet are trying to scam people.Read the original at Ars Technica