Fraudsters try to scare users with BSOD-themed ads

Sep 29, 2015 20:43 GMT  ·  By

Google's AdWords platform is the Internet's biggest advertising platform, allowing individuals and businesses to promote their offerings by placing ads in search results based on a list of keywords.

According to a recent Malwarebytes warning, cyber-criminals have found a way to exploit Google's advertising service in a covert and sneaky way, buying ads for popular keywords, and redirecting users to pages where they're served scareware.

As per researchers, in this recent campaign, ads were being shown to users searching YouTube and other related terms on Google. These ads appeared at the top of the search results, so users would be able to easily spot them.

What has intrigued both us and the Malwarebytes team is that these malvertisements (as malicious ads are called in the industry) showed the target URL as YouTube's domain, and even if hovered over, still showed the target URL on YouTube's site.

If users did click the link, they were redirected to a page where a BSOD (Blue Screen of Death) ad was shown, created to scare unsavvy and non-technical users.

BSOD ads, a trend that's resurfacing in scareware

This is a recent trend in malvertising tactics, and just yesterday we reported on a similar case which involved KickAss Torrents users.

Just like in this new case, users were shown a telephone number, which they were urged to call to fix their so-called "computer errors."

Of course, at the other end of these phone numbers users would find only scammers who would try to defraud them by having them pay various support and technical packages.

Digging around, the Malwarebytes found that this campaign was being carried out from two domains hosted on the 166.62.28.107 IP address, which has also been seen hosting 34 other fraudulent websites that we’re not going to mention here for your protection.

If there's one piece of advice we can give you is that blue screen of death messages never appear in a browser, so don't fall for that trick.

Google AdWords ads redirect users to scareware
Google AdWords ads redirect users to scareware

Photo Gallery (2 Images)

BSOD-themed scareware served via Google AdWords
Google AdWords ads redirect users to scareware
Open gallery