Researchers have uncovered a sophisticated tech support scam being propagated through Google ads, which effectively freeze screens on both Windows and Mac devices. This malicious tactic prompts users with alarming messages urging them to contact a fraudulent call center for assistance.
The advertisements have permeated numerous high-traffic websites, including those related to mapping services, weather forecasts, real estate, document hosting, and sports news. Investigations by the cybersecurity firm Netskope highlighted that from August 31 to September 14, users from 619 distinct organizations interacted with these harmful ads. Fortunately, Netskope’s security measures prevented any users from being exploited during this period.
A significant proportion of the organizations affected, approximately 62 percent, were located in the United States, while Japan and Australia were the next two most impacted countries. Given that Netskope’s monitoring covers only a fraction of overall internet activity, the actual number of individuals who encountered or fell victim to this scam is likely much greater. The firm identified over 250 Google Ads campaign IDs disseminated across at least 284 legitimate websites.
Netskope explained that the deceptive techniques employed in this scam transform a simple ad click into a terrifying scenario for users. The browser appears to freeze with a counterfeit security alert, which occupies the entire screen, conceals the cursor, and disables common exit commands. This design creates an overwhelming sense of urgency, compelling individuals to call the displayed phone number for what they believe is emergency assistance. It is essential to note that, while the computer may seem incapacitated, no actual lock has occurred, making the scam even more convincing.
Despite prevalent mockery directed toward individuals who fall for such scams, this criticism overlooks a significant segment of internet users who possess limited understanding of technology. Combined with the increasing complexity of web navigation and the urgency of completing tasks, this lack of knowledge renders many users vulnerable to exploitation. It is likely that some critics themselves have friends or family members who lack sufficient awareness about online safety.
In analyzing the tactics employed in this incident, relevant techniques from the MITRE ATT&CK framework can be identified, particularly regarding initial access and social engineering. The bait-and-switch approach used in the advertisement aligns with adversary tactics focused on deceiving users into divulging sensitive information or granting unauthorized remote access. By exploiting the trust placed in online ads, the perpetrators effectively leveraged these tactics to ensnare unsuspecting individuals.
As the cybersecurity landscape evolves, it is crucial for business owners to remain vigilant against such threats. Understanding the methodologies used in these scams can facilitate better awareness and stronger defenses, helping to protect both personal and organizational data from exploitation.