Now criminals pay to steal passwords

Cyber criminals are now even paying for sponsored Google ads

Ever more sophisticated, cyber criminals are now stealing passwords by tricking people into clicking on Google ads. And yes, that means they're having to shell out hard-stolen cash for them. Using Sponsored Links, criminals are pretending to lead people to authentic sites - only to take them on a phishing trip.

As flagged on the McAfee Avert Labs security blog, an instance of this has been uncovered. The main problem is that Sponsored Links hide their destination web address. Normally when you hover over a link, your browser will display the destination address in the bottom corner of your window. That's not the case with Sponsored Links.

"To get a sponsored link, you actually have to agree to pay for your clicks. And as this link was the top sponsored link, they had to have paid more money than other sponsors," explains McAfee's Allysa Myers

"[The link] would then direct them to a malicious site which contains a script which we detect as JS/Wonka.

"This site...contains a number of exploits. There are two particularly notable exploits in this lot - one for a recent QuickTime vulnerability and one for the ANI vulnerability from last month.

"The end result of this script is that it installs a downloader, for which detection is being added as Generic Downloader.ab. This downloader then downloads a PWS-Banker trojan to steal your online banking credentials."

Looping techniques

That lot sounds complicated, but basically clicking on the link sends you to the malicious site which downloads a trojan to nick your details.

Myers says malicious use of Google's many facilities isn't unusual. "In the past, we've seen looping techniques used for index hijacking in order to increase Page Rank, so that a page will show up higher in the list of returned results in Google's search results."

Google has now terminated the relevant advertising account. We can only wonder what the return on investment was like.

TOPICS
Contributor

Dan (Twitter, Google+) is TechRadar's Former Deputy Editor and is now in charge at our sister site T3.com. Covering all things computing, internet and mobile he's a seasoned regular at major tech shows such as CES, IFA and Mobile World Congress. Dan has also been a tech expert for many outlets including BBC Radio 4, 5Live and the World Service, The Sun and ITV News.

Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening