Google Ads Campaign Spreads Fake Security Alerts That Lock Browsers and Push Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Malicious ads are steering people to fake security warnings that appear to take over their browsers. The pages urge visitors to call a supposed support line, turning a routine ad click into an attempt to extract money, personal details or access to a computer.

The trap begins on a cloud-hosted page with a loading spinner and an ordinary-looking online store. Nothing alarming appears at first.

That opening avoids suspicion before showing a warning tailored to the visitor’s operating system. Netskope Threat Labs researchers identified the browser-based scam kit while investigating cloud-hosted pages.

Netskope said in a report shared with Cyber Security News (CSN) that the operation relies on paid Google ads and hidden code that waits for human interaction before revealing the fake alert.

From August 31 to September 14, 2026, researchers observed the kit reaching at least 619 organizations through more than 250 ad campaign IDs across at least 284 legitimate publisher sites. They counted 457 scam hosts. Those figures show exposure, not confirmed infections or losses.

Google Ads Campaign Spreads Fake Security Alerts

Traffic records carried ad-click markers on nearly all observed visits, pointing to paid placements rather than ordinary search results.

The ads appeared through normal inventory on popular maps, weather, property, document-hosting and sports sites. The publishers were not reported as compromised, an important distinction.

This shows how malicious ads can deliver malware or send visitors into other dangerous experiences without taking over the website showing the ad. Here, the first page displayed a spinner before becoming a storefront, then springing a fake security emergency.

The page also waits for a mouse movement before opening its hidden instructions. That test avoids automated scanners that do not move a cursor.

It then decrypts a hidden server address, retrieves a Windows or Mac version of the locker and builds the warning inside browser memory.

No separate locker file crosses the network for scanners to inspect. If the remote server fails or decryption goes wrong, the storefront stays visible instead.

Netskope compared this stealth to other browser scareware; earlier coverage of the CypherLoc browser locking kit shows how fake support warnings can also hide behind encrypted code.

Fake Alerts Create a Crisis

On Windows, the page imitates a Microsoft Defender scan and displays layered infection warnings. On a Mac, it uses Apple-themed alerts. Both repeatedly show a support number, suggesting a call is the only way to fix the supposed problem.

The first click switches the browser to full screen, hiding tabs and the address bar. The page conceals the pointer, interferes with exit shortcuts, plays alert sounds and deliberately makes the browser lag.

A flashing black warning and a tab-close prompt add to the pressure, but the computer itself is not locked, even though it looks convincing.

Like the fake Microsoft security scan documented in another scam, the warning is theater rather than evidence of a real infection. The report describes a browser-based payload and a push to call scammers; it does not establish that merely opening this page installs malware on the computer.

The intended next step is more dangerous: a caller could be pressed to pay for nonexistent repairs, disclose financial information or grant remote access. Similar fake support alert campaigns show why an on-screen phone number should not be treated as proof that a security provider is involved.

If the page appears, do not call its number. Netskope advises holding Escape for a few seconds to leave full screen, then closing the tab. If that fails, use Task Manager on Windows or Force Quit on a Mac to close the browser and reopen it without restoring the previous session.

The affected organizations were mostly in the United States, at about 62%, followed by Japan at 16% and Australia at 14%, based on ad-click geography. The lesson is simple: a webpage demanding an immediate support call is a scam, even when the browser makes leaving feel difficult.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Google Ads Campaign Spreads Fake Security Alerts That Lock Browsers and Push Malware appeared first on Cyber Security News.