Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain
Malicious Google Ads Campaign Targets Ledger Hardware Wallet (TL-2026-2673), also tracked as HTML.Phish.Ledger, is a high-severity phishing campaign, first published 2026-09-26. It has no confirmed attribution, affects Ledger Ledger hardware wallet users / Ledger Live setup and, maps to 12 MITRE ATT&CK techniques (T1036.005, T1071.001, T1102.002), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2673
- Threat ID
- TL-2026-2673
- Also known as
- HTML.Phish.Ledger
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-26
- Last reviewed
- 2026-09-26
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency digital assets, consumer retail individuals, financial services
- Target regions
- North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Malicious Google Ads Campaign Targets Ledger Hardware Wallet
Malware and tooling: hCaptcha
Since at least August 2026, threat actors have run fraudulent Google Ads impersonating Ledger that route victims through Google Cloud Storage buckets and rotating Vercel-hosted redirects to a Google Sites page hosting a fake device-verification interface with BIP-39 wordlist autocomplete, tricking victims into typing their Secret Recovery Phrase and allowing wallets to be drained without the physical device. Zscaler ThreatLabz publicly flagged the active campaign in late August 2026 and published full technical analysis on September 25, 2026 (detection name HTML.Phish.Ledger), corroborated the same day by an independent Security Boulevard mirror with matching indicators.
How Malicious Google Ads Campaign Targets Ledger Hardware Wallet works
Threat actors are abusing a chain of entirely legitimate, trusted cloud services — Google Ads, Google Cloud Storage (GCS), Vercel, and Google Sites — to deliver a credential-phishing page targeting Ledger hardware wallet users. The campaign is run through what Zscaler ThreatLabz describes as a 'long-standing, verified advertiser account' registered in Germany that researchers assess may itself have been compromised rather than newly fraudulently created, letting the ads inherit Google's trust signals (the ad displayed 'google.com' as its destination and boasted '10L+ visits in the past month'). Victims searching for Ledger-related terms in the United States, Europe, and parts of Asia are served the sponsored ad; clicking it sends them through a GCS bucket (e.g. storage.googleapis.com/apf-leg-ad-23798/), then to a Vercel-hosted intermediate application whose subdomain rotates every 15-20 minutes (observed values include soyyoo-cwpc5n0e.vercel.app, rpc-gbz5.vercel.app, whyavc-qwmv6stx.vercel.app, router-wdoi.vercel.app, and node-f1ey.vercel.app), and finally to a Google Sites page (e.g. sites.google.com/view/start-ledger-wallet) whose visible URL inherits Google's own domain, embedding the actual phishing interface inside an iframe served from the Vercel origin.
The phishing interface closely mimics Ledger's official device-setup workflow: it prompts the victim to select a device type (Windows, macOS, Linux, mobile), plays simulated progress messages ('Connecting your Ledger,' 'Initializing Firmware Update'), asks for device-ownership confirmation, and then prompts for the 24-word Secret Recovery Phrase (SRP). To increase the illusion of legitimacy and completion rate, the page fetches the full 2,048-word BIP-39 English wordlist from a bundled endpoint (api/bip39-english.txt) and implements live autocomplete as the victim types each word — the same UX behavior as Ledger's genuine tooling. The kit captures the recovery phrase twice: after the first submission it displays a fake 'Invalid seed. Please re-enter your recovery phrase carefully' error to harvest a second, corroborating entry before redirecting the victim to a benign-looking landing page, reducing suspicion. Throughout the flow the page monitors keypresses, touches, and mouse movement, and loads an invisible-mode hCaptcha widget at submission time — both used to fingerprint and filter out automated security-scanner traffic rather than real victims, extending the infrastructure's operational lifetime against takedown/scanning efforts. Captured recovery phrases are POSTed to the attacker-controlled Vercel backend.
Because a BIP-39 Secret Recovery Phrase is the master key material for a hardware wallet, possession of it lets an attacker restore the wallet in any compatible software and drain all associated cryptocurrency holdings without ever needing physical access to the victim's Ledger device. No CVE or software vulnerability is involved — the entire chain is social engineering built on abuse of legitimate advertising and hosting platforms (malvertising, GCS, Vercel, Google Sites) to evade URL-reputation and brand-protection filters that would flag a directly-registered lookalike domain.
MITRE ATT&CK techniques used in TL-2026-2673
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1497.002 User Activity Based Checks; T1684.001 Impersonation
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication
execution
Credential Access
Resource Development
T1583.006 Web Services; T1583.008 Malvertising; T1586.003 Cloud Accounts; T1608.005 Link Target
Impact
Affected products and versions in Malicious Google Ads Campaign Targets Ledger Hardware Wallet
- Ledger — Ledger hardware wallet users / Ledger Live setup and device-verification workflow (impersonated, not a software vulnerability)
Vulnerable versions: Not version-specific — social-engineering attack targets end users of any Ledger hardware wallet model
Fixed in: Not applicable — no software vulnerability; mitigation is user awareness and takedown of phishing infrastructure
Remediation for Malicious Google Ads Campaign Targets Ledger Hardware Wallet
Immediate actions
- Never enter a Ledger Secret Recovery Phrase (or any hardware-wallet seed phrase) into a website, browser extension, or desktop/mobile app screen — it should only ever be entered on the physical device itself
- Treat any 'device verification', 'firmware update', or 'synchronization' flow that asks for a recovery phrase in a browser as fraudulent and abandon it immediately
- Verify the destination of Ledger-branded ads and links independently by navigating directly to ledger.com rather than clicking sponsored search results or Google Sites/Vercel-hosted pages
- Report suspicious 'Ledger' Google Ads to Google Ads Safety and to Ledger's own phishing-report channel
Workarounds
- Only perform firmware updates and wallet setup/restoration through the official Ledger Live application downloaded directly from ledger.com, never through a browser flow reached via an ad or third-party link
- Bookmark ledger.com directly and disable/ignore sponsored search results when looking for Ledger support or software
Longer-term hardening
- Deploy brand-impersonation and typosquat/URL-monitoring coverage that also tracks abuse of legitimate SaaS hosting (storage.googleapis.com, *.vercel.app, sites.google.com) as phishing infrastructure, not just directly-registered lookalike domains
- Advertiser-account security hardening (mandatory MFA, anomalous-activity alerting, and ad-content review) to reduce the risk of verified accounts being hijacked and repurposed for malvertising
- User awareness training for cryptocurrency holders on multi-hop redirect chains that abuse trusted cloud platforms to bypass URL-reputation filtering
Timeline of Malicious Google Ads Campaign Targets Ledger Hardware Wallet
- Zscaler ThreatLabz later assesses the malvertising campaign has been active since August 2026; users begin reporting sponsored 'Ledger Official' Google results appearing for searches like 'Ledger Wallet' (exact day within August not disclosed).
- A fake 'Invalid seed. Please re-enter your recovery phrase carefully' error forces victims to submit their recovery phrase a second time; both submissions are sent to the attacker-controlled Vercel backend (guarded by an invisible-mode hCaptcha and keypress/mouse-movement bot checks) before the victim is redirected to a benign-looking landing page.
- The Google Sites page embeds a phishing interface in an iframe that walks victims through fake device selection, simulated 'Connecting your Ledger'/'Initializing Firmware Update' messages, and a device-ownership confirmation prompt before requesting the Secret Recovery Phrase, using a fetched 2,048-word BIP-39 wordlist for live autocomplete.
- Victims clicking the fraudulent ad are routed through Google Cloud Storage bucket paths (e.g. storage.googleapis.com/apf-leg-ad-23798/) to rotating Vercel-hosted intermediate domains (e.g. soyyoo-cwpc5n0e.vercel.app, rotating every 15-20 minutes), then to a Google Sites page (e.g. sites.google.com/view/start-ledger-wallet) whose visible URL appears to belong to Google itself.
- Zscaler ThreatLabz publicly flags the active campaign, identifying it as abusing a compromised, verified Google Ads advertiser account to target Ledger Secret Recovery Phrases.
- Bitcoin Foundation publishes an independent write-up corroborating the campaign, citing Zscaler's August 27 disclosure and adding user-protection and recovery guidance.
- Zscaler assigns detection name HTML.Phish.Ledger (ID 4f9dc76e-38af-43a0-8161-4fe679cb310b) to the phishing kit; Security Boulevard and Malware News mirror the report the same day with matching indicators.
- Zscaler ThreatLabz (analyst Prakhar Shrotriya) publishes full technical analysis of the campaign, including the complete redirect-chain IOCs (GCS buckets, Vercel domains, Google Sites URLs).
Sources cited for Malicious Google Ads Campaign Targets Ledger Hardware Wallet
More in phishing
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
Detection coverage for TL-2026-2673
As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2673 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.