I will never click another sponsored link on Google again

An angler using Google as bait.
(Image credit: Chris Stein)

There's an increasingly concerning phenomenon happening one the web right now, one that's seeing scammers buying up top ad spots on Google in order to spread malicious code. Often impersonating well known apps such as WhatsApp, they can blend seamlessly with harmless ads. Unless you know the exact URL of the app you're trying to download, you could find yourself downloading something harmful.

We've been watching phishing tactics evolve over the years, and while buying ads to impersonate free and open-source apps isn't a new method for would-be scammers, it seems to have increased along with the trend in NFT and cryptocurrency investments going on all over the internet. 

When there's billion-dollar phish to be caught, you can bet they're baiting that area up good. Just this week, in fact, NFT God's 'entire digital livelihood' was drained after clicking an official-looking OBS link.

Even hardware manufacturers have been subject to this kind of mimicry, such as the fake AMD driver download link found on Google. A mirror EVGA site was spotted on Google late last year, too.

In looking into the happenings, Bleeping Computer found that a disturbing number of top Google ad positions have been taken up by phishing scams, and only some of them have actually been flagged by antivirus products.

Among them, a fake link for the bootable USB flash drive creation tool Rufus sits at the top of Google, rounded off with the word "pro" so as to make the link more attractive to potential victims. The link takes you to compressed file download, hidden behind a safe-looking file transfer service. This is known as a zip bomb, or decompression bomb, and is one of the more difficult to detect tactics.

Scammers have also been spotted using what's known as typosquatting, as in the case of "notepad-plus-plus.com" which is close enough to the expected URL that many don't suspect it as being malicious.

Other times, scammers will hide behind a seemingly legitimate tech company, as in the case of 7-ZIP, WinRAR, and VLC found on a malicious link-filled site impersonating an Indian web design company known as Zensoft Tech.

Window shopping

Windows 11 Square logo

(Image credit: Microsoft)

Windows 11 review: What we think of the new OS
How to install Windows 11: Safe and secure install
What you need to know before upgrading: Things to note before downloading the latest OS
Windows 11 TPM requirements: Microsoft's strict security policy

"Google uses its best efforts to review and validate the information provided by advertisers as part of these verification programs," says the company's verification terms, "but in doing so does not guarantee or assume responsibility for advertiser content or activity."

Google's own policy on abusing the ad network makes it clear that "Computer viruses, ransomware, worms, trojan horses, rootkits, keyloggers, diallers, spyware, rogue security software and other malicious programmes or apps" are not allowed to be linked through ads. This refers to both "ads and any software that your site or app either hosts or links to".

However, it also notes that "Violations of this policy won't lead to immediate account suspension without prior warning. A warning will be issued, at least seven days, prior to any suspension of your account." I suppose this is to give hacked sites a chance to get their URL back if they themselves have been made victims.

Among calls for social media companies to be held more accountable for the content posted on their sites, I'm betting web users won't put up with Google's somewhat blaise attitude on this for long.

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Seattle, USA - Jul 24, 2022: The South Lake Union Google Headquarter entrance at sunset.
'New year, new low, Microsoft'—even the search engines are firing shots on social media now, as Google employees take aim at Bing over 'long history of tricks'
A Bing search bar that looks a lot like a Google search bar.
Microsoft's latest trick to get you using Bing is disguising it as Google
Fuzzy children's show character with blue fur but rendered monstrous with void eyes and rows of shark teeth
Creator of horror game Poppy Playtime sues Google for refusing to remove 'bait-and-switch scam' apps that pretend to be the real thing then charge users up to $95 for literally nothing
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
Google being pushed to sell off Chrome is likely a good thing, but don't cheer on the decision just yet
An AI-generated image, posted to Activision's socials, of a fake Crash Bandicoot game that doesn't actually exist.
Finding a new and inventive way to annoy everybody, Activision has company use AI to generate fake advertisements for games that don't exist
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Recently appointed Intel CEO Lip-Bu Tan.
Here comes Intel's new CEO: a semiconductor veteran that won the same prestigious award as Jensen Huang and Lisa Su
BURBANK, CALIFORNIA - AUGUST 15: Protestors attend the SAG-AFTRA Video Game Strike Picket on August 15, 2024 in Burbank, California. (Photo by Lila Seeley/Getty Images)
8 months into their strike, videogame voice actors say the industry's latest proposal is 'filled with alarming loopholes that will leave our members vulnerable to AI abuse'
Orithopter shooting down another in Dune
Dune: Awakening confirms air-to-air combat in ornithopters
live action Jimbo the Jester from Balatro holding a playing card and addressing the camera
LocalThunk forbids AI-generated art on the Balatro subreddit: 'I think it does real harm to artists of all kinds'
Inzoi - A Zoi's face in three graphical presets showing a progression from a slightly blurry minimum specs to a higher fidelity recommended specs.
Oh great, the full Inzoi system requirements are posted and I'm barely above the minimum specs so I guess my Zois will be beautifully blurry
Mark Darrah
BioWare veteran says a big delay is better than lots of little ones, because sometimes you just gotta 'burn it down and take the other fork in the road'