Fraudsters Exploited Google Ads to Misappropriate $59 Million in Cryptocurrency

12

Analysts discovered that fraudsters were utilizing Google Ads to deceive cryptocurrency users by evading ad verification and content quality control systems. These methods enabled perpetrators to steal nearly $59 million in cryptocurrency over the last nine months.

Fraudsters Exploited Google Ads to Misappropriate $59 Million in Cryptocurrency0

As reported by Scam Sniffer, Google’s advertising services became a tool for scammers who promoted counterfeit versions of well-known cryptocurrency websites over the past nine months. Users suffered losses totaling approximately $58.98 million in digital assets due to these fraudulent activities.

A comprehensive study initiated in March by cybersecurity firm SlowMist and later reported by Scam Sniffer analysts revealed that attackers were actively bypassing Google Ads’ ad verification and content quality control systems. Specifically, to complicate the auditing of Google Ads, scammers employed:

  • regional targeting strategies;
  • page-switching techniques;
  • web redirects.

Fraudsters utilized MS Drainer, a phishing script that enables the transfer of digital assets without the owner’s confirmation, to pilfer cryptocurrencies through fraudulent websites. The creators of this malware offer it for sale on various forums at a fixed price of $1,499.99, with additional modules for the script priced between $500 and $1,000. Unlike other similar hacking tools, the developers of MS Drainer do not take a percentage of the funds acquired through the script, ensuring complete anonymity.

Scam Sniffer analysts successfully identified 10,072 phishing sites that were advertised via Google Ads and incorporated MS Drainer in the past nine months. Among these were replicas of prominent cryptocurrency projects such as Lido, DefiLlama, Radient, Zapper, Orbiter Finance, and Stargate. In total, fraudsters managed to mislead 63,210 cryptocurrency users during this timeframe.

In November, cybersecurity specialists discovered that scammers were actively employing counterfeit social media applications like Skype and Telegram for phishing purposes.

Сообщение Scammers Used Google Ads to Steal $59M in Crypto появились сначала на CoinsPaid Media.