Description
A phishing campaign has been identified, targeting Microsoft advertisers through malicious Google Ads. Attackers are leveraging sponsored search results to impersonate Microsoft’s advertising platform, aiming to steal user credentials and bypass two-factor authentication (2FA) measures.
Attack Details
In this campaign threat actors purchase Google Ads that appear when users search for terms like Microsoft Ads. These ads redirect users to phishing sites that closely mimic the legitimate Microsoft Ads login page. To evade detection, attackers use advanced techniques such as redirection and cloaking. When unwanted IP addresses, including those from VPNs, bots, or security scanners, attempt to access the malicious ads, they are redirected to harmless white pages. Meanwhile, genuine users are subjected to a Cloudflare challenge to verify their authenticity before being redirected to the phishing site.
The phishing sites are designed to closely resemble Microsoft’s official domain, using deceptive URLs such as ads[.]mcrosoftt[.]com. Upon attempting to log in, victims encounter fake error messages prompting them to reset their passwords. Additionally, the phishing kit is capable of attempting to bypass two-factor authentication (2FA), a common feature in modern phishing campaigns.
To further obfuscate their tactics, attackers employ a unique deception method if users navigate directly to the malicious domain instead of clicking through the ad, they are met with a rickroll, an internet prank intended to mock visitors. This extra layer of misdirection serves to deter analysis and further disguise the true intent of the phishing campaign.
Indicators of Compromise (IOCs)
The following domains have been identified as associated with this phishing campaign:
Remediation
To mitigate the risks associated with this phishing campaign, users and organizations are advised to implement the following best practices:
The Guyana National CIRT recommends that users and administrators review this alert and apply it where necessary.
PDF Download: Microsoft Advertisers Account Hacked Using Malicious Google Ads
References