Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain

Malicious Google Ads Campaign Targets Ledger Hardware Wallet (TL-2026-2673), also tracked as HTML.Phish.Ledger, is a high-severity phishing campaign, first published 2026-09-26. It has no confirmed attribution, affects Ledger Ledger hardware wallet users / Ledger Live setup and, maps to 12 MITRE ATT&CK techniques (T1036.005, T1071.001, T1102.002), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2673

Threat ID
TL-2026-2673
Also known as
HTML.Phish.Ledger
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-26
Last reviewed
2026-09-26
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency digital assets, consumer retail individuals, financial services
Target regions
North America, Europe, Asia
Detection rules
9
Indicators of compromise
19

Malware and tooling in Malicious Google Ads Campaign Targets Ledger Hardware Wallet

Malware and tooling: hCaptcha

Since at least August 2026, threat actors have run fraudulent Google Ads impersonating Ledger that route victims through Google Cloud Storage buckets and rotating Vercel-hosted redirects to a Google Sites page hosting a fake device-verification interface with BIP-39 wordlist autocomplete, tricking victims into typing their Secret Recovery Phrase and allowing wallets to be drained without the physical device. Zscaler ThreatLabz publicly flagged the active campaign in late August 2026 and published full technical analysis on September 25, 2026 (detection name HTML.Phish.Ledger), corroborated the same day by an independent Security Boulevard mirror with matching indicators.

How Malicious Google Ads Campaign Targets Ledger Hardware Wallet works

Threat actors are abusing a chain of entirely legitimate, trusted cloud services — Google Ads, Google Cloud Storage (GCS), Vercel, and Google Sites — to deliver a credential-phishing page targeting Ledger hardware wallet users. The campaign is run through what Zscaler ThreatLabz describes as a 'long-standing, verified advertiser account' registered in Germany that researchers assess may itself have been compromised rather than newly fraudulently created, letting the ads inherit Google's trust signals (the ad displayed 'google.com' as its destination and boasted '10L+ visits in the past month'). Victims searching for Ledger-related terms in the United States, Europe, and parts of Asia are served the sponsored ad; clicking it sends them through a GCS bucket (e.g. storage.googleapis.com/apf-leg-ad-23798/), then to a Vercel-hosted intermediate application whose subdomain rotates every 15-20 minutes (observed values include soyyoo-cwpc5n0e.vercel.app, rpc-gbz5.vercel.app, whyavc-qwmv6stx.vercel.app, router-wdoi.vercel.app, and node-f1ey.vercel.app), and finally to a Google Sites page (e.g. sites.google.com/view/start-ledger-wallet) whose visible URL inherits Google's own domain, embedding the actual phishing interface inside an iframe served from the Vercel origin.

The phishing interface closely mimics Ledger's official device-setup workflow: it prompts the victim to select a device type (Windows, macOS, Linux, mobile), plays simulated progress messages ('Connecting your Ledger,' 'Initializing Firmware Update'), asks for device-ownership confirmation, and then prompts for the 24-word Secret Recovery Phrase (SRP). To increase the illusion of legitimacy and completion rate, the page fetches the full 2,048-word BIP-39 English wordlist from a bundled endpoint (api/bip39-english.txt) and implements live autocomplete as the victim types each word — the same UX behavior as Ledger's genuine tooling. The kit captures the recovery phrase twice: after the first submission it displays a fake 'Invalid seed. Please re-enter your recovery phrase carefully' error to harvest a second, corroborating entry before redirecting the victim to a benign-looking landing page, reducing suspicion. Throughout the flow the page monitors keypresses, touches, and mouse movement, and loads an invisible-mode hCaptcha widget at submission time — both used to fingerprint and filter out automated security-scanner traffic rather than real victims, extending the infrastructure's operational lifetime against takedown/scanning efforts. Captured recovery phrases are POSTed to the attacker-controlled Vercel backend.

Because a BIP-39 Secret Recovery Phrase is the master key material for a hardware wallet, possession of it lets an attacker restore the wallet in any compatible software and drain all associated cryptocurrency holdings without ever needing physical access to the victim's Ledger device. No CVE or software vulnerability is involved — the entire chain is social engineering built on abuse of legitimate advertising and hosting platforms (malvertising, GCS, Vercel, Google Sites) to evade URL-reputation and brand-protection filters that would flag a directly-registered lookalike domain.

MITRE ATT&CK techniques used in TL-2026-2673

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1497.002 User Activity Based Checks; T1684.001 Impersonation

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

execution

T1204.001 Malicious Link

Credential Access

T1552.004 Private Keys

Resource Development

T1583.006 Web Services; T1583.008 Malvertising; T1586.003 Cloud Accounts; T1608.005 Link Target

Impact

T1657 Financial Theft

Affected products and versions in Malicious Google Ads Campaign Targets Ledger Hardware Wallet

  • Ledger — Ledger hardware wallet users / Ledger Live setup and device-verification workflow (impersonated, not a software vulnerability)
    Vulnerable versions: Not version-specific — social-engineering attack targets end users of any Ledger hardware wallet model
    Fixed in: Not applicable — no software vulnerability; mitigation is user awareness and takedown of phishing infrastructure

Remediation for Malicious Google Ads Campaign Targets Ledger Hardware Wallet

Immediate actions

  • Never enter a Ledger Secret Recovery Phrase (or any hardware-wallet seed phrase) into a website, browser extension, or desktop/mobile app screen — it should only ever be entered on the physical device itself
  • Treat any 'device verification', 'firmware update', or 'synchronization' flow that asks for a recovery phrase in a browser as fraudulent and abandon it immediately
  • Verify the destination of Ledger-branded ads and links independently by navigating directly to ledger.com rather than clicking sponsored search results or Google Sites/Vercel-hosted pages
  • Report suspicious 'Ledger' Google Ads to Google Ads Safety and to Ledger's own phishing-report channel

Workarounds

  • Only perform firmware updates and wallet setup/restoration through the official Ledger Live application downloaded directly from ledger.com, never through a browser flow reached via an ad or third-party link
  • Bookmark ledger.com directly and disable/ignore sponsored search results when looking for Ledger support or software

Longer-term hardening

  • Deploy brand-impersonation and typosquat/URL-monitoring coverage that also tracks abuse of legitimate SaaS hosting (storage.googleapis.com, *.vercel.app, sites.google.com) as phishing infrastructure, not just directly-registered lookalike domains
  • Advertiser-account security hardening (mandatory MFA, anomalous-activity alerting, and ad-content review) to reduce the risk of verified accounts being hijacked and repurposed for malvertising
  • User awareness training for cryptocurrency holders on multi-hop redirect chains that abuse trusted cloud platforms to bypass URL-reputation filtering

Timeline of Malicious Google Ads Campaign Targets Ledger Hardware Wallet

  • Zscaler ThreatLabz later assesses the malvertising campaign has been active since August 2026; users begin reporting sponsored 'Ledger Official' Google results appearing for searches like 'Ledger Wallet' (exact day within August not disclosed).
  • A fake 'Invalid seed. Please re-enter your recovery phrase carefully' error forces victims to submit their recovery phrase a second time; both submissions are sent to the attacker-controlled Vercel backend (guarded by an invisible-mode hCaptcha and keypress/mouse-movement bot checks) before the victim is redirected to a benign-looking landing page.
  • The Google Sites page embeds a phishing interface in an iframe that walks victims through fake device selection, simulated 'Connecting your Ledger'/'Initializing Firmware Update' messages, and a device-ownership confirmation prompt before requesting the Secret Recovery Phrase, using a fetched 2,048-word BIP-39 wordlist for live autocomplete.
  • Victims clicking the fraudulent ad are routed through Google Cloud Storage bucket paths (e.g. storage.googleapis.com/apf-leg-ad-23798/) to rotating Vercel-hosted intermediate domains (e.g. soyyoo-cwpc5n0e.vercel.app, rotating every 15-20 minutes), then to a Google Sites page (e.g. sites.google.com/view/start-ledger-wallet) whose visible URL appears to belong to Google itself.
  • Zscaler ThreatLabz publicly flags the active campaign, identifying it as abusing a compromised, verified Google Ads advertiser account to target Ledger Secret Recovery Phrases.
  • Bitcoin Foundation publishes an independent write-up corroborating the campaign, citing Zscaler's August 27 disclosure and adding user-protection and recovery guidance.
  • Zscaler assigns detection name HTML.Phish.Ledger (ID 4f9dc76e-38af-43a0-8161-4fe679cb310b) to the phishing kit; Security Boulevard and Malware News mirror the report the same day with matching indicators.
  • Zscaler ThreatLabz (analyst Prakhar Shrotriya) publishes full technical analysis of the campaign, including the complete redirect-chain IOCs (GCS buckets, Vercel domains, Google Sites URLs).

Sources cited for Malicious Google Ads Campaign Targets Ledger Hardware Wallet

More in phishing

Detection coverage for TL-2026-2673

As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2673 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats