Skip Navigation

Malicious Google Search Ads can now fake the displayed URL to push malware downloads

Most people know at this point that when searching for a popular software package to download, you should be very careful to avoid clicking on any of the search ads that appear, as this has become an extremely common vector for distributing malware to unsuspecting users.

If you thought that you could identify these malicious ads by checking the URL below the ad to see if it directs to the legitimate site, think again! Malware advertisers have found a way to use Google's Ad platform to fake the URL shown with the ad to make it appear like a legitimate ad for the product when in fact, clicking the ad will redirect to an attacker controlled site serving malware.

Don't click on search ads or, even better, use an ad-blocker so that you never see them in the first place!

  • This has been a feature of Google Ads forever. It isn't even "found a way" it is just a box to fill in the ad manager.

    Presumably this is so that they can use tracking links to analyze the performance of the ad without making the URL "ugly". But it is easy to abuse. (Although I think Google attempts to do some checks, but of course those are always going to be unreliable.)

  • Had this happen searching for Argos (a large British retailer). The sponsored result sent me to a survey scam that cloned the Argos site, quickly reported it.