An ad click becomes a fake emergency
Security researchers have identified a large tech-support scam campaign in which malicious Google ads made Windows and Mac browsers appear frozen, then displayed urgent warnings directing users to fraudulent call centers. The ads appeared on legitimate maps, weather, real-estate, document-hosting and sports sites, turning ordinary browsing into a convincing imitation of a compromised computer.
Netskope observed users at 619 customer organizations click the malicious ads between August 31 and September 14. The security company blocked the content for those customers, so its data did not show them completing the scam. Researchers tracked more than 250 Google Ads campaign identifiers across at least 284 legitimate publisher sites. About 62 percent of the observed organizations were in the United States, with Japan and Australia the next most represented countries.
The malicious page filled the display, concealed the address bar and cursor, intercepted common exit keys and deliberately slowed the browser. Sounds, lag and repeated warning messages reinforced the impression of a serious infection. Attempts to close the browser could refresh the scare screen instead. The code waited for mouse movement before showing the warning and decrypted itself in browser memory, behavior that can make automated detection more difficult. It also tailored the display to Windows or macOS.
The underlying device was not actually locked. The purpose was to create enough urgency for a victim to call the displayed number. People who did so could be pressured to pay fees, reveal personal information or allow remote access to the computer. Those follow-on actions, rather than the browser display itself, created the greatest risk.
How to get out safely
Users should not call a number shown in an unsolicited security warning. In many cases, holding the Escape key for several seconds can force the browser out of full-screen mode and restore keyboard control, allowing the tab to be closed. On Windows, Task Manager can be opened with Control-Shift-Escape to end the browser. On a Mac, Command-Option-Escape opens the force-quit window. The browser can then be reopened without restoring the previous session.
Google said it was investigating the campaigns and would act against accounts that violated its policies. The company did not explain why its screening missed the ads or confirm that every campaign had been removed, according to the report.
The incident demonstrates why familiar advice about avoiding suspicious websites is insufficient. Advertising supply chains can place hostile content on established sites that users reasonably trust. The safest response is to treat a browser message demanding a phone call as a scam, exit the browser through system controls if necessary, and never provide payment, credentials or remote access to an unsolicited caller.



