
Threat Analysts have uncovered a sophisticated and ongoing series of malvertising and phishing campaigns exploiting Google Search ads to target graphic design professionals and high-profile organizations. These campaigns employ deceptive advertising tactics to lure unsuspecting victims into downloading malicious software or compromising sensitive employee portals.
Malvertising Campaigns Target Graphic Designers
At least ten malvertising campaigns have been identified by Silent Push, hosted exclusively on two IP addresses: 185.11.61[.]243 and 185.147.124[.]110. The malicious sites linked to these IP addresses have been strategically promoted through Google Search advertising campaigns. Unsuspecting graphic design professionals searching for industry tools are led to malicious downloads when they click on these ads.
Domains associated with these IP ranges have been launched continuously since November 13, 2024. Despite the persistence and volume of these campaigns, Google’s advertising team has not implemented sufficient measures to halt them, highlighting significant gaps in their oversight mechanisms.
Phishing Campaign Targets Payroll Systems
The Threat researchers also warn of another phishing campaign that uses malicious Google Ads to conduct payroll redirect scams. Attackers purchase search ads with brand keywords to promote phishing pages, spoofing well-known HR platforms and organizations, including Workday, the California Employment Development Department (EDD), Kaiser Permanente, Macy's, New York Life, and Roche.
These phishing websites are designed to deceive victims into entering login credentials for employee portals. Once inside, attackers alter the banking information to redirect payroll funds to accounts under their control. Silent Push notes that these campaigns are further bolstered by stolen credentials, including social security numbers, likely obtained from underground forums.
Abuse of Legitimate Tools and Infrastructure
Threat actors are leveraging legitimate website builders such as Leadpages, Mobirise, and Wix to rapidly create new phishing domains. These domains are hosted on infrastructure linked to registrars favored by attackers, including Dynadot, Porkbun, and Namecheap. This rapid setup capability allows threat actors to stay ahead of security defenses by continuously deploying fresh domains.
The researchers have observed dedicated IP ranges connected to these campaigns, with tactics shifting in alignment with specific timeframes. Such operational adaptability underscores the calculated and professional approach employed by these threat actors.
Executive Summary and Key Observations
Tracking threat actors requires complex analysis and access to robust intelligence. However, the methods used in these campaigns involve basic techniques—such as identifying IP addresses hosting malicious domains—that any junior threat analyst could perform. Yet, these campaigns have persisted, largely unchecked, for nearly a month.
The Threat Analysts emphasize that conducting a simple IP address lookup and investigating associated domains could have flagged this malicious activity earlier. The lack of proactive measures by Google’s advertising team raises concerns about the effectiveness of current detection and prevention strategies.
Recommendations
To mitigate these threats, organizations and individuals are urged to:
-
Verify the authenticity of search ads and URLs before clicking, especially when downloading software or accessing HR portals.
-
Deploy robust threat detection systems capable of identifying phishing and malvertising campaigns.
-
Educate employees on recognizing and avoiding phishing attempts.
-
Monitor payroll systems for unauthorized changes to banking information.
-
Collaborate with cybersecurity partners to share threat intelligence and stay ahead of emerging tactics.
The Threat Analysts findings serve as a critical reminder of the evolving tactics used by threat actors to exploit legitimate platforms for malicious purposes. Proactive measures and collaboration among industry stakeholders are essential to countering these threats effectively.
Protect Your Organization with StormWarning!
Cyber threats are evolving at an alarming rate, with attackers exploiting even trusted platforms like Google Ads to target professionals and organizations. From malvertising campaigns to payroll redirect scams, no business is safe without proactive defenses.
StormWarning! is your all-in-one solution to stay ahead of emerging cybersecurity threats. Designed to enhance your security posture with precision and efficiency, StormWarning! offers:
-
Automated NIST Cybersecurity Audits: Identify vulnerabilities and gaps in your defenses with minimal disruption to daily operations.
-
Real-Time Threat Detection: Stay informed about malvertising campaigns, phishing attacks, and other critical threats targeting your industry.
-
Customized Training: Address weaknesses with tailored lessons from our Cybersecurity LMS, featuring over 100 expert-designed courses.
-
Actionable Insights: Generate detailed reports with clear recommendations for improving policies, processes, and systems.
With StormWarning!, you can:
- Detect and mitigate threats before they harm your organization.
- Empower employees with the knowledge to spot and avoid phishing scams.
- Protect sensitive data, payroll systems, and employee accounts from targeted attacks.
Don’t wait for your organization to become the next victim. Secure your operations and safeguard your future with StormWarning!
Contact us today to schedule a demo and see how StormWarning! can fortify your defenses against modern cyber threats.
StormWarning! – Your Frontline Defense Against Cybercrime.
Protect. Prevent. Prevail.
TAKE STEPS TO PROTECT YOUR BUSINESS NOW!
CYBER THREATS ARE ON THE RISE—ARE YOU PREPARED?
Over 2,200 cyberattacks happen every day—one every 39 seconds.
AI-driven phishing scams are on the rise—don't fall victim to them!
95% of breaches are due to human error. Strengthen your defenses now.
