Researchers uncovered a large-scale tech-support scareware campaign delivered through Google Ads that freezes browsers on both Windows and macOS and displays urgent fake infection warnings urging users to call a phone number. Netskope tracked the campaign from Aug. 31 to Sept. 14, observing clicks from users in 619 customer organizations, identifying more than 250 Google Ads campaign IDs running across at least 284 legitimate publisher sites (maps, weather, real-estate, document-hosting, sports). The fake warnings hide the address bar, disable common exit keys, hide the cursor, play sounds, and refresh if users try to close the tab, all to pressure victims into granting remote access, paying fees, or handing over personal data. About 62 percent of impacted organizations were in the U.S.; exposure is almost certainly far higher than Netskope’s visibility shows.
The scareware delivers its payload only after mouse movement and keeps its code encrypted until displayed in browser memory, a design that prevents detection by many endpoint security products and ad scanners. Google says it is investigating and enforces a zero-tolerance policy, but remediation is simple: press and hold Esc to exit full screen, use Task Manager (Ctrl-Shift-Esc) on Windows or Force Quit (Cmd-Option-Esc) on Mac to close the browser, then reopen without restoring the previous session. Never call numbers shown in such warnings; legitimate companies do not advise calling a phone number to fix an infection.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.