Header image

Microsoft Impersonated in Dodgy Google Ads

The phishing page sought to capture users' login credentials and two-factor authentication codes.

Fake Google ads impersonated Microsoft in a bid to exfiltrate user’s credentials.

According to an analysis by Malwarebytes, attacks aimed to lure targets looking for "Microsoft Ads" and other similar terms on Google Search into clicking on nefarious sponsored links, which redirect to a phishing page resembling the "ads.microsoft[.]com" site.

The Hacker News reported that the phishing page sought to capture users' login credentials and two-factor authentication codes later for future account takeovers.

Additional findings revealed that Brazil accounted for most of the phishing domains used in the campaign. Google has reiterated its commitment to combat malicious ads that target user data. 

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Upcoming Events

No events found.