Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users
Malicious Google Ads campaign delivers browser-locking fake (TL-2026-2651) is a high-severity tracked intrusion set, first published 2026-09-25. It has no confirmed attribution, maps to 10 MITRE ATT&CK techniques (T1027, T1036, T1059.007), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2651
- Threat ID
- TL-2026-2651
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target regions
- united states of america, japan, australia
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Malicious Google Ads campaign delivers browser-locking fake
Malware and tooling: Fake 'Microsoft Defender Security Center' scan (Windows variant), ShopEase decoy storefront, Tech Support Scam (TSS) kit, browser-locking scareware kit, hidden C2 server for encrypted locker retrieval
Active malvertising campaign (observed Aug 31 - Sep 14, 2026) uses paid Google ads on at least 284 legitimate publisher sites to steer victims to cloud-hosted tech-support-scam pages that lock the browser with a fake security alert and force a call to a bogus support line. The kit waits for mouse movement, decrypts a hidden C2 address with a hardcoded AES key in-browser, and assembles an OS-tailored locker entirely in memory; victims are pressured into paying for nonexistent repairs, disclosing financial details, or installing remote-access software. Reached at least 619 organizations via 457 scam hosts across 250+ ad campaigns; no confirmed infections, payments, or losses.
How Malicious Google Ads campaign delivers browser-locking fake works
DRIVE-BY MALVERTISING CHAIN. Netskope Threat Labs observed a cloud-hosted tech-support-scam (TSS) kit delivered via paid Google Ads inventory on popular maps, weather, property, document-hosting and sports publisher sites (at least 284 legitimate publisher domains; publishers were not compromised). Traffic records carried ad-click markers (gclid, gad_source, gad_campaignid) on nearly all visits, confirming paid placements, with clicks flowing through Google's own click-redirect (googleads.g.doubleclick.net). Victims land on a loading spinner page presenting Cancel/Continue buttons, then an ordinary-looking online storefront branded ShopEase with no obvious malicious content; the malicious code waits for a single mouse movement - a bot filter that stalls automated scanners that do not move a cursor - before proceeding to the next stage.
RUNTIME C2 AND IN-MEMORY LOCKER. The kit decrypts a hardcoded AES key-signed hidden server address at runtime, retrieves an encrypted locker payload tailored to the visitor's operating system, and decrypts it with a second cryptographic key. The fake warning is constructed directly in browser memory rather than delivered as an inspectable standalone page, so no separate locker file crosses the network for scanners to inspect; if the remote server cannot be contacted or decryption fails, the victim simply remains on the ShopEase storefront.
BROWSER LOCKOUT MECHANICS. On the first click the page forces fullscreen via the requestFullscreen() API, hiding the browser tabs, address bar and UI; conceals the mouse cursor; calls the browser's Keyboard Lock API to swallow the Escape key and exit shortcuts; plays repeated alert sounds; deliberately runs busy loops to lag and stutter the browser; and flashes a black warning screen with text urging the user not to restart or operate the computer, alongside a tab-close confirmation dialog with additional scam messaging. The computer itself is not actually locked - the disruptive behavior is confined to the browser - but the experience is engineered to pressure the victim into calling the repeatedly displayed support number as the supposed only fix.
OS-TAILORED IMPERSONATION AND FRAUD END-STATE. On Windows the kit impersonates a convincing Microsoft Defender Security Center scan with layered infection warnings; on macOS, a similar fake security warning styled around Apple's ecosystem. Callers reached by the displayed telephone number could be pressured to pay for nonexistent repairs, disclose sensitive personal and financial information, install remote-access software, or hand control of their computers to the criminals. No actual malware installation from the malicious page was observed and the report does not establish that opening the page installs malware.
SCALE AND ASSESSMENT. During the campaign window (Aug 31 - Sep 14, 2026) at least 619 organizations were reached via 457 scam hosts across more than 250 Google Ads campaign IDs; by ad-click geography the split was approximately 62% United States, 16% Japan, and 14% Australia. Netskope's inline protection detects the kit under the signature Generic.Phishing Tech Support Scam Kit Detected. The figures show exposure, not confirmed infections or losses. Infrastructure rotation across many short-lived hosts makes simple domain-based blocking less reliable, and prior iterations of the same tradecraft (Netskope's Feb 2026 Bing Ads cluster hosted in Azure Blob Storage redirecting via highswit[.]space, BleepingComputer's Aug 2023 Amazon-impersonation ad leading to a fake Defender alert with a fullscreen lock and session-restore trap) show the pattern is recurring. Defenders should combine browser telemetry, DNS monitoring, URL reputation and advertising-related indicators, and should treat an unexpected security warning combined with extreme urgency and a telephone number as a scam signal.
MITRE ATT&CK techniques used in TL-2026-2651
Stealth
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Execution
T1059.007 JavaScript; T1204.001 Malicious Link
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1608.005 Link Target
Remediation for Malicious Google Ads campaign delivers browser-locking fake
Immediate actions
- Do not call the telephone number displayed by any security alert that locks the browser - it is the scam endpoint
- If trapped on a fullscreen scam page, hold the Escape key for a few seconds to exit fullscreen, then close the tab
- If Escape fails, force-close the browser via Task Manager (Windows) or Force Quit (macOS) and reopen WITHOUT restoring the previous session, which otherwise returns to the scam page
- Never grant remote access, install software requested by the caller, enter payment details, or disclose passwords to an inbound 'support' caller
Workarounds
- Browse with a purpose-built low-privilege profile and disable automatic session restore to prevent the session-restore trap
- Gate outbound web traffic from users to new or low-reputation domains during active campaigns
Longer-term hardening
- Deploy browser isolation for high-risk browsing to contain browser-based scareware and phishing
- Enforce ad-blocking and anti-tracking at the edge; filter ads network-wide during active malvertising campaigns
- Use URL reputation, DNS filtering and newly-registered/lookalike domain blocklists; expect infrastructure rotation across many short-lived scam hosts
- Correlate browser telemetry (forced fullscreen, Keyboard Lock API usage, cursor concealment), URL reputation and endpoint telemetry to detect the kit's behavior cluster
- Deliver security-awareness training: an unexpected security warning combined with extreme urgency and a phone number should always be treated as a scam
- Report malicious ad creatives and associated advertiser accounts to Google to accelerate account takedowns
Timeline of Malicious Google Ads campaign delivers browser-locking fake
- BleepingComputer documented an earlier iteration of the same pattern: a Google ad impersonating Amazon led to a fake Microsoft Defender alert (claiming ads(exe).finacetrack(2).dll infection) with a fullscreen lock and a session-restore trap that reopened the scam page.
- Companion campaign observed: from ~16:00 UTC a spike of users across 48 organizations clicked tech-support-scam links in Azure Blob Storage reached via malicious Bing ads for innocuous queries; all victims in the US across healthcare, manufacturing and technology.
- Netskope Threat Labs published 'Malicious Bing Ads Lead to Widespread Azure Tech Support Scams' documenting a companion TSS cluster (Feb 2, 2026, 48 US organizations) hosted in Azure Blob Storage and redirected via highswit[.]space.
- First observed by Netskope Threat Labs: malicious Google Ads on legitimate publisher inventory began steering victims to cloud-hosted browser-locking tech-support-scam pages.
- Last day of the campaign's observed activity window; the kit had reached at least 619 organizations via 457 scam hosts across 250+ Google Ads campaign IDs.
- Netskope Threat Labs published 'A Fake Security Locker, Delivered by Google Ads', documenting the cloud-hosted tech-support-scam kit delivered via paid Google Ads.
- Cyber Security News published coverage of the Netskope Threat Labs research on the Google Ads browser-locking scareware campaign.
Sources cited for Malicious Google Ads campaign delivers browser-locking fake
- A Fake Security Locker, Delivered by Google Ads
- Malicious Google Ads Campaign Delivers Browser Locking Scareware to Over 600 Organizations
- Fake Microsoft Defender Alerts Spread Through Google Ads in Browser-Hijacking Tech Support Scam + Video
- Malicious Bing Ads Lead to Widespread Azure Tech Support Scams
- Sneaky Amazon Google ad leads to Microsoft support scam
More in threat intel
- UK establishes National Centre for Information Defence to counter Russian state disinformation operations
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass Disinformation, Malvertising, and Cryptojacking
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation
Detection coverage for TL-2026-2651
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2651 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.