www.netskope.com Google Ads Deliver Tech Support Scam Kit with Fake Security Alerts
Article Content
- •The scam targets users via Google Ads on legitimate websites.
- •619 organizations were exposed, primarily in the U.S., Japan, and Australia.
- •The kit uses mouse movement detection to evade automated scanners.
A tech support scam kit has been identified that uses Google Ads to deliver fake security alerts, locking browsers and targeting users across at least 619 organizations. The campaign was observed between August 31 and September 14, 2026, with 62% of affected organizations located in the United States. Victims are lured by ads on legitimate sites, leading to a loading spinner that transitions to a fake online store branded 'ShopEase.' The kit employs mouse movement detection to evade automated analysis, activating only after user interaction. Once triggered, it decrypts a command-and-control address and retrieves a tailored fake security alert for either Windows or macOS systems. The fake alerts mimic legitimate security software, pressuring users to call a bogus support number. Netskope Threat Labs reported that the scam creates the illusion of a locked browser, making it difficult for users to exit or regain control.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CypherLoc in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…