ads – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 01 Sep 2025 12:57:27 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 ads – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Brokewell Android malware delivered through fake TradingView ads https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/ https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/#respond Mon, 01 Sep 2025 12:57:27 +0000 https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/

Brokewell Android malware delivered through fake TradingView ads

Cybercriminals are abusing Meta’s advertising platforms with fake offers of a free TradingView Premium app that spreads the Brokewell malware for Android.

The campaign targets cryptocurrency assets and has been running since at least July 22nd through an estimated 75 localized ads.

Brokewell has been around since early 2024 and features a broad set of capabilities that include stealing sensitive data, remote monitoring and control of the compromised device.

Taking over the device

Researchers at cybersecurity company Bitdefender investigated the ads in the campaign, which use the TradingView branding and visuals and lure potential victims with the promise of a free premium app for Android.

Fake TradingView ad leading to Brokwell malware
sourcce Bitdefender

They note that the campaign was specifically designed for mobile users, as accessing the ad from a different operating system would lead to harmless content.

Clicking from Android, however, redirected to a webpage mimicking the original TradingView site that provided a malicious tw-update.apk file hosted at tradiwiw[.]online/

“The dropped application asks for accessibility, and after receiving it, the screen is covered with a fake update prompt. In the background, the application is giving itself all the permissions it needs,” the researchers say in a report this week..

Furthermore, the malicious app also tries to obtain the PIN for unlocking the device by simulating an Android update request that needs the lockscreen password.

Fake TradingView app tries to obtain Android device lockscreen code
source: Bitdefender

According to Bitdefender, the fake TradingView app is “an advanced version of the Brokewell malware” that comes “with a vast arsenal of tools designed to monitor, control, and steal sensitive information:”

  • Scans for BTC, ETH, USDT, bank account numbers (IBANs)
  • Steals and exports codes from Google Authenticator (2FA bypass)
  • Steals account by overlaying fake login screens
  • Records screens and keystrokes, steals cookies, activates the camera and microphone, and tracks the location
  • Hijacks the default SMS app to intercept messages, including banking and 2FA codes
  • Remote control – can receive commands over Tor or Websockets to send texts, place calls, uninstall apps, or even self-destruct

The researchers provide a technical overview of how the malware works and an extended list of supported commands that includes more than 130 rows.

Bitdefender says that this campaign is part of a larger operation that initially used Facebook ads impersonating “dozens of well-known brands” to target Windows users.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/feed/ 0 56221
Google confirms data breach exposed potential Google Ads customers’ info https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/ https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/#respond Mon, 11 Aug 2025 01:20:14 +0000 https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/

Google Ads

Google has confirmed that a recently disclosed data breach of one of its Salesforce CRM instances involved the information of potential Google Ads customers.

“We’re writing to let you know about an event that affected a limited set of data in one of Google’s corporate Salesforce instances used to communicate with prospective Ads customers,” reads a data breach notification shared with BleepingComputer.

“Our records indicate basic business contact information and related notes were impacted by this event.”

Google says the exposed information includes business names, phone numbers, and “related notes” for a Google sales agent to contact them again.

The company says that payment information was not exposed and that there is no impact on Ads data in Google Ads Account, Merchant Center, Google Analytics, and other Ads products.

The breach was conducted by threat actors known as ShinyHunters, who have been behind an ongoing wave of data theft attacks targeting Salesforce customers.

While Google has not shared how many individuals were impacted, ShinyHunters says the stolen information contains approximately 2.55 million data records. It is unclear if there are duplicates within these records.

ShinyHunters further told BleepingComputer that they are also working with threat actors associated with “Scattered Spider, who are responsible for first gaining initial access to targeted systems.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

The threat actors are now referring to themselves as “Sp1d3rHunters,” to illustrate the overlapping group of people who are involved in these attacks.

As part of these attacks, the threat actors conduct social engineering attacks against employees to gain access to credentials or trick them into linking a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

The threat actors then download the entire Salesforce database and extort the companies via email, threatening to release the stolen data if a ransom is not paid.

These Salesforce attacks were first reported by the Google Threat Intelligence Group (GTIG) in June, with the company suffering the same fate a month later.

Databreaches.net reported that the threat actors have already sent an extortion demand to Google. After publishing the story, ShinyHunters told BleepingComputer that they demanded 20 Bitcoins, or approximately $2.3 million, from Google to not leak the data.

“I don’t care about ransoming Google anyway, I just sent them a bogus email for the lulz of it,” said the threat actor.

ShinyHunters says they have since switched to a new custom tool that makes it easier and quicker to steal data from compromised Salesforce instances.

In an update, Google recently acknowledged the new tooling, stating that they have seen Python scripts used in the attacks instead of the Salesforce Data Loader.

Update 8/9/25: Added further information about the extortion demand.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/feed/ 0 52579
JSCEAL Scam Targets Crypto Users with 35,000 Malicious Ads https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/ https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/#respond Mon, 04 Aug 2025 03:18:19 +0000 https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/

Cybersecurity company Check Point has warned that over 10 million people may have been exposed to malware through fake crypto apps promoted via online ads.

The campaign, known as “JSCEAL”, has been active since at least March 2024, according to a July 29 report by Check Point.

It works by imitating nearly 50 well-known cryptocurrency platforms, including Binance



$5.76B

and Kraken



$195.4M

, to trick users into downloading harmful software.

How to Use Crypto? 5 Rewarding Strategies Explained (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Check Point stated that Meta’s internal data showed over 35,000 such ads were displayed in early 2025. The firm estimated that at least 3.5 million people in the EU saw these ads.

Since the campaign also mimicked platforms in Asia, where social media use is widespread, the global reach is believed to be much higher. However, Check Point explained that not every view results in infection, and the total number of actual victims is hard to confirm.

The malware is built with JavaScript, which runs without needing any further input from the user. Check Point said the code is hard to examine because it is heavily disguised.

If installed, the malware collects private information from the device. This includes things like keyboard activity that can reveal passwords, Telegram session data, stored login credentials, and browser cookies.

It can also affect crypto wallet browser extensions like MetaMask, which may increase the risk of unauthorized access.

Recently, Sentinel Labs discovered a hacking campaign that uses fake video meetings and disguised software updates to plant malware on Apple computers. How does the malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/feed/ 0 51335
Amazon Explores AI Voice Ads Through Alexa+ Conversations https://earlybirdsinvest.com/amazon-explores-ai-voice-ads-through-alexa-conversations/ https://earlybirdsinvest.com/amazon-explores-ai-voice-ads-through-alexa-conversations/#respond Sat, 02 Aug 2025 03:23:21 +0000 https://earlybirdsinvest.com/amazon-explores-ai-voice-ads-through-alexa-conversations/

Amazon is exploring the idea of including ads in conversations with Alexa+, its upgraded artificial intelligence (AI) voice assistant.

According to a report by TechCrunch, CEO Andy Jassy stated during the company’s second-quarter earnings call that ads could play a useful role as people interact more with Alexa+ in multi-step conversations.

Jassy noted, “I think over time, there will be opportunities, as people are engaging in more multi-turn conversations, to have advertising play a role to help people find discovery, and also as a lever to drive revenue”.

What is Blockchain? (Animated Examples + Explanation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Alexa+ is part of Amazon’s strategy to improve its older voice assistant by making it more capable and easier to talk to. Millions of users already have access to it, and it is meant to compete with new AI voice tools from OpenAI, Google, and Perplexity.

Currently, Alexa+ is free for Prime members, who pay $14.99 per month for the membership. There is also a separate subscription option for Alexa+ at $20 a month. Jassy suggested that more pricing options may be added in the future, which may possibly include one that removes ads.

Until now, advertising within Alexa has been limited. Sometimes, users might hear a short audio ad between songs or see a product promotion on the Echo Show screen.

On July 28, Google introduced a new feature in the United Kingdom called “AI Mode”. How does it work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/amazon-explores-ai-voice-ads-through-alexa-conversations/feed/ 0 50986
Sydney Sweeney’s American Eagle campaign: How the ads became a national conversation https://earlybirdsinvest.com/sydney-sweeneys-american-eagle-campaign-how-the-ads-became-a-national-conversation/ https://earlybirdsinvest.com/sydney-sweeneys-american-eagle-campaign-how-the-ads-became-a-national-conversation/#respond Sat, 02 Aug 2025 03:00:40 +0000 https://earlybirdsinvest.com/sydney-sweeneys-american-eagle-campaign-how-the-ads-became-a-national-conversation/

Declaring that an actor has great jeans should technically be a boring way to sell denim. And yet, an American Eagle ad featuring Euphoria star Sydney Sweeney and some poorly conceived wordplay has broken everyone’s brains.

Last week, the mall brand unveiled a series of ads featuring Sweeney sporting their fall collection. One video shows her filming herself on the floor with a dog; another depicts her fixing the engine of a car. All of them end with a booming, male voice declaring “Sydney Sweeney has great jeans,” with the copy displayed in large font.

The spots that caught the internet’s ire are arguably the most provocative, each an obvious riff on Brooke Shields’ infamous 1980 Calvin Klein commercial, in which the then-15-year-old actor recites facts about genetics (“certain genes may…fade away,” Shields notes) while posing in the company’s denim. The Sweeney ad plays on the same jeans/genes pun, but in a much clumsier fashion and in a very complicated cultural landscape.

“My body’s composition is determined by my genes,” Sweeney starts in one video that’s since been deleted from American Eagle’s social media. The camera starts to zoom in on her chest before she lightly scolds the operator. “Hey, eyes up here.” In another, she says, “Genes are passed down from parents to offspring, often determining traits like hair color, personality, and even eye color.” The camera pans to Sweeney’s eyes, and she says, “My jeans are blue.”

The same pun is used in a poster that reads “Sydney Sweeney has great jeans” with the word “genes” crossed out above it. It immediately raised questions about the language of the ad, as well as its blonde-haired, blue-eyed messenger: Are we supposed to want pants or Aryan features?

In its most innocent interpretation, it reads as passe in its use of a “conventionally attractive” spokesmodel. Many, however, have deemed the American Eagle ads a racist dog whistle, some even calling it Nazi propaganda. Meanwhile, voices on the right, including the White House, have celebrated the ads as a middle finger to liberals and “woke.”

The ads are…weird. Why bother buying the jeans if you don’t have the genes it celebrates? Plus, Sweeney’s role in it, given the partisan nonsense she’s been drafted into in the recent past, raises an eyebrow. American Eagle has since clarified its intentions with the ads, stating that the marketing was solely meant to highlight the jeans. “We’ll continue to celebrate how everyone wears their AE jeans with confidence, their way,” read an Instagram statement on August 1. Sweeney has yet to respond.

Regardless, the whole kerfuffle says less about Sweeney herself — or even American Eagle’s marketing team — than about the politically fraught state of media in the US.

A lightning rod on the left and a symbol — voluntary or not — for the right

To comprehend the layers of the controversy, one has to understand the politically charged and paradoxical nature of Sweeney’s image and career thus far.

After landing supporting roles in The Handmaid’s Tale and Sharp Objects, Sweeney received her big break on the HBO teen drama Euphoria in 2019 as self-destructive teenager Cassie Howard. Her role on the show, which often sees her character nude or wearing cleavage-baring tops, has contributed to much of Euphoria’s seedy reputation, while also shaping Sweeney’s bombshell image. The show also helped launch her as an aspiring “prestige” actor; her performance earned critical praise, as well as an Emmy nomination in 2022. She earned an additional nomination that year for her role in HBO’s The White Lotus.

This acclaim was followed by the release of the 2023 romantic-comedy Anyone But You, which she starred in opposite Glen Powell and co-produced. The Shakespeare adaptation was marketed with PR-orchestrated rumors about Sweeney and Powell’s relationship and went on to earn over $200 million globally. By all accounts, it seemed poised to be the next big movie star, with all the makings of a savvy entrepreneur.

Then, around 2024, things started to get strange — and loudly. That year, Sweeney hosted Saturday Night Live. The episode featured several jokes about her breasts, and she wore a low-cut dress during “goodnights.” This elicited multiple op-eds from conservative outlets claiming that Sweeney, and her willingness to participate in gags about her own sex appeal, signaled a return to both a pre-MeToo climate and “traditional” beauty standards. In fact, this wasn’t the first time Sweeney had been linked to conservative ideology, correctly or incorrectly. In 2022, she sparked outrage for photos she posted from her mother’s Western-themed birthday party, which showed relatives wearing MAGA hats and Blue Lives Matter gear in the background. She claimed they were merely ironic costumes, an explanation that failed to quell questions about her political leanings.

Today, the idea that Sweeney might be an undercover agent for MAGA — and voluntary bait for incels — is somewhere between a conspiracy theory and a meme. (No matter that she has supported progressive causes, like Black Lives Matter, appeared at the GLAAD Awards, and said she believes “that a woman has the right to be able to decide over her body.”) Her endorsement work includes brand deals with the country-inspired HeyDude and personal care company Dr. Squatch. By the time she released a soap supposedly made from her own bathwater with the latter company, her critics seemed exhausted by her whole schtick.

“I think her and her camp probably think that they’re playing into [her sexuality] with a wink and a smile and being self-aware about her being consumed as this sex object and that she is in control,” says Garrett Mireles, a New York and Tennessee-based brand strategist and copywriter. “How that’s received in the public eye isn’t as nuanced.”

Mireles says the fact that Sweeney is an actor cast in other people’s work and ideas complicates her ability to control the way her image comes across and who exactly she wants to appeal to.

“Sweeney doesn’t get to control the message as much as a musician does,” Mireles says. “Sabrina Carpenter, for example, is able to exert a sense of humor in her sexuality and to be a little bit more overtly tongue-in-cheek.”

Everything feels like bait in our current culture war

The American Eagle ads felt especially trollish because they seemed to hit on both of the accusations looming over Sweeney’s career: She’s too sexualized, and she’s promoting some sort of right-wing agenda. In this case, the right-coded overtones of the ad — heralding a blonde, white woman’s genes as the epitome of beauty and “goodness” — hit a lot harder.

Any implication of “good genes,” pun or not, would ring alarms in our political climate. Currently, ICE and the Trump administration have undertaken the most aggressive deportation effort in years, including the gleeful construction of an alligator-surrounded detainment center that has been compared to a concentration camp. When talking about crimes committed by immigrants, President Donald Trump has said there are a “lot of bad genes in our country.” Meanwhile, Health Department secretary Robert F. Kennedy has been accused of promoting “soft eugenics” through his proposals to eliminate vaccines and lifesaving health services that would disproportionately impact certain populations.

Outside of politics, pop culture is also feeling a lot more Trump-friendly these days. From country artists dominating the charts from trad-wife content online to celebrities cozying up to the president, it seems like everyone is embracing the reign of MAGA and the tastes of his voter base. This has made every piece of pop culture, from influencers to ad campaigns, fodder for viewing through a MAGA lens. At the same time, the right has made efforts to insert itself into cultural moments and ephemera, from animation memes to superhero-movie discourse. More and more regular people are vigilant about the way pop culture can be used to push political messages. But it can be difficult to know what does and doesn’t deserve our energy and cultural attention.

Still, it’s hard not to feel like we’ve all been effectively “got” by a brand that most of us haven’t thought about since high school, one that has not sparked this much fervent discussion in its entire existence. But even American Eagle might not have put as much thought into the ads as its critics did. Peter Bray, founder and executive creative director at advertising agency Bray & Co, says the American Eagle ad may be more innocent than we assume, the result of a “first thought” concept as opposed to anything intentionally controversial.

“I don’t think in any way this was their intent,” Bray says. “They thought they had a lightbulb moment of creativity and didn’t think about the bigger cultural picture.”

Whether or not it meant it, American Eagle illuminated a winning engagement strategy for the second Trump era: Flirt with the public’s fear (or excitement) about fascism — with the help of Sydney Sweeney.

]]>
https://earlybirdsinvest.com/sydney-sweeneys-american-eagle-campaign-how-the-ads-became-a-national-conversation/feed/ 0 50974
Block ads for the whole fam for less than your monthly streaming services https://earlybirdsinvest.com/block-ads-for-the-whole-fam-for-less-than-your-monthly-streaming-services/ https://earlybirdsinvest.com/block-ads-for-the-whole-fam-for-less-than-your-monthly-streaming-services/#respond Sun, 15 Jun 2025 17:58:01 +0000 https://earlybirdsinvest.com/block-ads-for-the-whole-fam-for-less-than-your-monthly-streaming-services/

]]>
https://earlybirdsinvest.com/block-ads-for-the-whole-fam-for-less-than-your-monthly-streaming-services/feed/ 0 42203
Google claims users find ads in AI search ‘helpful’ https://earlybirdsinvest.com/google-claims-users-find-ads-in-ai-search-helpful/ https://earlybirdsinvest.com/google-claims-users-find-ads-in-ai-search-helpful/#respond Mon, 26 May 2025 13:32:00 +0000 https://earlybirdsinvest.com/google-claims-users-find-ads-in-ai-search-helpful/

Google

Google AI mode and AI Overviews now have ads, which, according to the search engine giant, are “helpful.”

At the Google Marketing Live event last week, Google confirmed it has started rolling out ads to AI mode and AI Overviews in the US, which create new “opportunities for customers.”

While I haven’t seen ads in AI Overviews, some users spotted them last week, and these ads appear below the AI Overviews, followed by the traditional blue links.

Google AI ads
Ads in Google AI overviews (Desktop)

In a support document spotted by SER, Google described ads in AI search results as a new way to find information on the web.

SEO consultant Gagan Ghotra pointed out an interesting excerpt in the document that claims users find ads in these AI search results helpful.

“Google internal data shows that people have been finding the ads within AI Overviews helpful because they can quickly connect with relevant businesses, products, and services to take the next step at the exact moment they need them,” the company wrote in the document.

Google won’t share the numbers or methodology of its “internal data,” but it wants you to believe that ads are helpful, especially in AI search results.

Ads aren’t necessarily bad, but they’re certainly not helpful when they mislead users or appear above the actual content and disrupt the flow.

Google reported $72.5 billion in advertising revenue in its last quarterly report, and it’s expected to increase as ads expand beyond the blue links.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-claims-users-find-ads-in-ai-search-helpful/feed/ 0 38418
Fake Semrush ads used to steal SEO professionals’ Google accounts https://earlybirdsinvest.com/fake-semrush-ads-used-to-steal-seo-professionals-google-accounts/ https://earlybirdsinvest.com/fake-semrush-ads-used-to-steal-seo-professionals-google-accounts/#respond Fri, 21 Mar 2025 17:47:20 +0000 https://earlybirdsinvest.com/fake-semrush-ads-used-to-steal-seo-professionals-google-accounts/

Fake Semrush ads used to steal SEO professionals’ Google accounts

A new phishing campaign is targeting SEO professionals with malicious Semrush Google Ads that aim to steal their Google account credentials.

Malwarebytes researcher Jerome Segura and SEO strategist Elie Berreby believe that the threat actor is after Google Ads accounts that would enable them to create new malvertising campaigns.

This type of “cascading fraud” has been gaining traction recently, as Malwarebytes uncovered in January a similar operation where fake Google Ads hosted on Google Sites targeted Google Ads accounts.

“We believe the criminals behind it likely regrouped and switched to a less direct approach, yet one that might deliver just as much,” explains Malwarebytes.

In this latest case, the cybercriminals abuse the Semrush brand, a popular software-as-a-service (SaaS) platform used for SEO, online advertising, content marketing, and competitive research.

Malicious search results
Malicious search results
Source: Malwarebytes

Semrush is widely used by digital marketers, advertisers, e-commerce businesses, and large enterprises, including 40% of Fortune 500 companies.

Because Semrush integrates with Google Analytics and Google Search Console, customers often link valuable Google accounts containing sensitive business data—like revenue metrics, marketing strategies, and customer behavior, all attractive targets for cybercriminals.

Berreby told BleepingComputer that behind the campaign is a Brazilian threat group who specializes in targeting SaaS platforms and now is employing a particularly crafty technique.

“The scammers’ ultimate goal are Google accounts. But their second best option are SaaS credentials,” explained Berreby.

“If an enterprise Google account was linked in the past, there’s a possibility of exfiltrating sensitive Google data without compromising the Google account itself.”

Semrush campaign

In the latest campaign, cybercriminals use Google Ads to promote malicious Semrush results when users enter related search terms.

Clicking the ad takes users to a phishing site that looks like Semrush and uses the “semrush” domain names but with a different top-level domain than the legitimate company (semrush.com).

Some malicious domains used in the campaign are “semrush[.]click,” “semrush[.]tech,” auth.seem-rush[.]com,” “semrush-pro[.]co,” and “sem-rushh[.]com.”

Most of these domains remain online, but not all load the phishing page, suggesting that the threat actor is filtering their targets based on geographical location and other criteria.

Phishing page
Phishing page
Source: Malwarebytes

The fake login page mimics Semrush’s interface but doesn’t offer the standard sign-in options, forcing visitors to log in via “Log in with Google” only.

When users enter their Google login details, the information is sent directly to the attackers.

Since many Semrush accounts are integrated with Google Analytics (GA) and Google Search Console (GSC), the threat actors may gain access to sensitive business data without compromising Semrush itself.

Accessible info post-compromise
Accessible info post-compromise
Source: Malwarebytes

Regarding the persistence of malicious Google Ads and the tech giant’s failure to tackle this problem decisively, Berreby explained that it will take big decisions at the higher level to stop this.

“Jérôme Segura and I have had multiple chats with Google representatives in the past years about the cybersecurity risks of using Google Ads for malicious purposes. The answer from those well-meaning and hard-working people was always the same: ‘I’m just a cog in a huge machine’

“The problem is the people we talk with at Google cannot address the underlying issues because they are not decision-makers. They are diligently doing their best at an individual level, but that’s not enough, and frankly, that’s not acceptable for a giant tech company like Google that uses the most advanced machine learning solutions.”

Still, the CEO expert commended Google for responding quickly to their reports and taking down the malicious search results associated with the latest campaign.

To avoid getting trapped by Google Ads scams, avoid clicking on promoted/sponsored results, bookmark pages you access frequently to visit them directly, and always double-check that you landed on the official domain before logging in.

Using a password manager to fill out login boxes can also help because the data will be typed in on the domains the credentials were saved for.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/fake-semrush-ads-used-to-steal-seo-professionals-google-accounts/feed/ 0 26438