ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Phishing and fake Google ads

Kevin Cryan at Fortra’s PhishLabs describes how phishing campaigns are targeting financial institutions via Fake Google Ads

 

It has recently emerged that phishing attacks targeting US and Canadian financial institutions have been leveraging a weakness in Google’s ad service to direct customers to malicious sites. This approach represents one of the most successful tactics currently being used to carry out phishing campaigns.

 

For context, let’s first take a look at how ad links work. When presented with a Google Ad, users can see the URL the ad directs to. The same is true when the user moves a mouse over the ad, the destination of the ad link appears.

 

Before the user lands on the destination page however, they are redirected through Google’s servers so that they can track all the link clicks. Many organisations buying ads will also link to their own click-tracking services.

 

Therefore, users may end up being routed through multiple sites before arriving at their destination. In all cases, however, the ad text and mouse-over link still shows the final destination landing page.

 

Leveraging conditional redirects

Attackers abuse the fact that the URL shown in Google Ads is not the linked site but rather the final destination, including the redirects. They create fake ads with their own redirects, which they set up to lead to the legitimate site.

 

When Google traces these redirects, they see the appropriate site and the ads go on to display the legitimate URL. However, threat actors then configure the redirect to use certain criteria, such as geo-location, to direct users to malicious phishing sites.

 

These campaigns are also potentially using other obfuscation techniques to evade detection by Google. All the while, Google is still seeing that the ad is going to a legitimate site.

 

In the example below, the attackers have incorporated a redirect that is not only malicious but also contains logic that will hide its intended destination. When Google attempts to determine where the user will land, they see a legitimate credit union site, and as a result, will only display the credit union URL.

 

If the end user clicks on the ad, they will instead land on a different, malicious site, such as in this case where the redirect would only display the phishing site if the user IP was located in Minnesota.

 

 

 

 

 

Due to the fact these ads look legitimate and are presented on Google, which many would consider a trusted provider, these attacks have been very successful. Financial institutions are a prime high-value target and the phishing sites in question have been able to gather customer credentials and in turn have stolen significant amounts of money from accounts.

 

Identifying and preventing attacks

There are certain detection mechanisms that help detect and monitor these malicious ads while also working to take down the malicious redirects and phishing sites where possible. The Google team is working on implementing preventative measures.

 

Unfortunately, due to the fact that their legitimate customers leverage the same redirect behaviour, this kind of abuse is likely to continue. Additional policy changes will be required to stop threat actors from succeeding with this strategy.

 


 

Kevin Cryan is Director of Operational Intelligence at Fortra’s PhishLabs

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543