Security News > 2023 > January > Ransomware access brokers use Google ads to breach your network

Ransomware access brokers use Google ads to breach your network
2023-01-24 23:07

A threat actor tracked as DEV-0569 uses Google Ads in widespread, ongoing advertising campaigns to distribute malware, steal victims' passwords, and ultimately breach networks for ransomware attacks.

While there appear to be many threat actors abusing the Google Ads platform to distribute malware, two particular campaigns stand out, as their infrastructure was previously associated with ransomware attacks.

To make matters worse, Fernández discovered that a different but similar Google ads campaign was using infrastructure previously used by a threat group tracked as TA505, known to distribute the CLOP ransomware.

In this Google ads campaign, the threat actors distribute malware through websites pretending to be popular software, such as AnyDesk, Slack, Microsoft Teams, TeamViewer, LibreOffice, Adobe, and, strangely, websites for W-9 IRS forms.

While BleepingComputer did not contact Google regarding this article, we did contact them last week regarding a similar malware campaign distributed through Google ads.

The bad news is that the threat actors are constantly launching new ad campaigns and new sites, making it a giant game of whack-a-mole, and it doesn't feel like Google is winning.


News URL

https://www.bleepingcomputer.com/news/security/ransomware-access-brokers-use-google-ads-to-breach-your-network/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4895 2855 1622 10368