{"id":48582,"date":"2023-04-27T06:17:22","date_gmt":"2023-04-27T10:17:22","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=48582"},"modified":"2023-04-27T06:17:25","modified_gmt":"2023-04-27T10:17:25","slug":"crypto-users-lose-over-4m-through-phishing-urls-on-google-ads","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/crypto-users-lose-over-4m-through-phishing-urls-on-google-ads\/","title":{"rendered":"Crypto users lose over $4M through Phishing URLs on Google Ads"},"content":{"rendered":"\n<p>Blockchain analytics and data from Google Ads show that customers who visited fraudulent <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-hackers-use-500-phishing-domains-to-steal-nfts.html\" target=\"_blank\" rel=\"noreferrer noopener\">phishing websites <\/a>advertised by Google have lost over $4 million.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-57.png\" alt=\"Crypto users lose over $4M through Phishing URLs on Google Ads\" class=\"wp-image-48592\" width=\"734\" height=\"466\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-57.png 442w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-57-300x191.png 300w\" sizes=\"(max-width: 734px) 100vw, 734px\" \/><figcaption class=\"wp-element-caption\">Crypto users lose over $4M through Phishing URLs on Google Ads<\/figcaption><\/figure>\n\n\n\n<p>According to ScamSniffer, a Web3 anti-scam service provider, malicious advertisements for fraud websites have recently dominated Google ads searches. The URLs lead to fraudulent websites that provoke wallet login signature requests that compromise the addresses of users.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ \ud83d\udea8 A recent surge in phishing scams via Google search ads has led to users losing approximately $4 million.<br>ScamSniffer has investigated multiple cases where users clicked on malicious ads and were directed to fraudulent websites.<a href=\"https:\/\/twitter.com\/hashtag\/PhishingScams?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#PhishingScams<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> <a href=\"https:\/\/twitter.com\/hashtag\/GoogleAds?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#GoogleAds<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/vuKCgSuFnV\" target=\"_blank\">pic.twitter.com\/vuKCgSuFnV<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) <a href=\"https:\/\/twitter.com\/realScamSniffer\/status\/1651452380385509377?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 27, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Scammers have targeted several <a href=\"https:\/\/coinscreed.com\/staging\/introduction-to-decentralized-finance-defi-cryptocurrencies-and-smart-contract.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized finance (DeFi) protocols<\/a>, websites, and brands, including Zapper.fi, Lido, Stargate, Defillama, Orbital Finance, and Radiant. Slight modifications to official URLs make it challenging for users to identify malicious links.<\/p>\n\n\n\n<p>Several of the fraudulent websites in question have been linked to Ukrainian and Canadian advertisers based on an analysis of their metadata. The individuals responsible for the malicious advertisements use various methods to circumvent Google's ad review. This includes manipulating the Google Click ID parameter, which enables attackers to display a standard webpage during Google's ad review.<\/p>\n\n\n\n<p>Other malicious advertisements employ anti-debugging techniques to redirect users with developer tools enabled to a regular website, whereas a direct click leads to the malicious website. This also permits scammers to circumvent some of <a href=\"https:\/\/coinscreed.com\/staging\/google-ads-still-promote-crypto-phishing-sites-cz-binance.html\" target=\"_blank\" rel=\"noreferrer noopener\">Google Ads'<\/a> automated evaluations.<\/p>\n\n\n\n<p>ScamSniffer's database of on-chain data from addresses linked to malicious websites advertised on Google suggests that over 3,000 users have had $4.16 million stolen in the past month.<\/p>\n\n\n\n<p>The anti-scam service monitored the on-chain movement of funds to various exchange and blending services, such as SimpleSwap, Tornado Cash, KuCoin, and Binance.<\/p>\n\n\n\n<p>Using advertising analysis platforms, <a href=\"https:\/\/www.scamsniffer.io\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ScamSniffer <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>concludes that crypto-related fraud website promotion is profitable. Between $1 and $2 is the average cost per hit for associated keywords.<\/p>\n\n\n\n<p>Assuming a conversion rate of 40% from 7,500 users clicking on malicious advertisements, fraudsters have spent approximately $15,000 on advertising, which has yielded a 276% return given the $4 million stolen to date.<\/p>\n\n\n\n<p>A report from the Russian cybersecurity and anti-virus provider Kaspersky forecasts a rise in crypto-related phishing attacks through 2022, with over 5 million phishing attacks identified in 2017.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain analytics and data from Google Ads show that customers who visited fraudulent phishing websites advertised by Google have lost over $4 million. According to ScamSniffer, a Web3 anti-scam service provider, malicious advertisements for fraud websites have recently dominated Google ads searches. The URLs lead to fraudulent websites that provoke wallet login signature requests that [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":48592,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[9313,1945,14304],"class_list":["post-48582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-google-ads","tag-crypto-scam","tag-phishing-urls"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-57.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/48582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=48582"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/48582\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/48592"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=48582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=48582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=48582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}