Back to Feed
Threat IntelligenceSep 28, 2026

Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts

Tech support scam kit uses Google Ads to deliver fake security alerts and lock browsers.

Summary

A tech support scam kit is leveraging Google Ads to distribute fake security alerts, making browsers appear locked and targeting users across hundreds of organizations. The campaign, observed by Netskope, uses a mouse movement trigger to evade automated analysis and displays convincing fake security alerts mimicking Microsoft Defender or Apple storefronts, pressuring users to call a support number.

Full text

Security Scams and FraudTech Support Scam Kit Uses Google Ads to Deliver Fake Security AlertsbyDeeba AhmedSeptember 28, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Google Ads deliver a tech support scam kit that shows fake security alerts, makes browsers appear locked and targets users across hundreds of organizations. A tech support scam kit is using Google Ads to deliver fake security alerts that make browsers appear locked while using techniques to evade automated analysis. Netskope Threat Labs observed exposure to the campaign across at least 619 organizations between August 31 and September 14, 2026. The 619 organizations represent Netskope’s observed exposure, not confirmed victims who lost money or data. According to the company, about 62% of the organizations were in the United States, followed by Japan at 16% and Australia at 14%. Netskope also identified more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites and 457 scam hosts. Mouse Movement Triggers the Scam The ads appeared through normal advertising inventory on legitimate maps, weather, real-estate, document-hosting, and sports sites. It is worth noting that the publishers were not compromised. Netskope traced most of the traffic to paid Google Ads rather than organic searches, based on Google advertising identifiers found in the URLs. After clicking an ad, users initially see a loading spinner with “Cancel” and “Continue” buttons before the page turns into an ordinary-looking online store branded “ShopEase.” The kit waits for a mouse movement before activating its hidden code. The “Loading…” spinner with two dead buttons and the ShopEase storefront that follows Netskope research revealed that this works as a filter because automated scanners and crawlers may not generate genuine mouse movement. Once triggered, the kit runs two decryption stages. It first recovers a hidden command-and-control (C2) address, then retrieves and decrypts a Windows or macOS version of the fake security locker. The decrypted locker is assembled inside browser memory instead of being downloaded as an inspectable file. If the C2 is unavailable or decryption fails, the page remains on the storefront. Fake Alerts Make the Browser Appear Locked On Windows, the locker imitates Microsoft Defender and displays a fake “Microsoft Defender Security Center” scan claiming the computer is infected. The macOS version uses a fake Apple storefront. Both display a support number and pressure users into calling it. “The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser,” Netskope Threat Labs noted in the blog post shared with Hackread.com, describing how the browser-based scam creates the appearance of a serious computer problem. The first click puts the browser into full-screen mode, removing the address bar and tabs from view. At the same time, the cursor disappears and the keyboard-lock API interferes with shortcuts such as Escape. Additionally, alert sounds and busy loops make the browser difficult to use, while a black warning urges users not to operate or restart the computer and to call the displayed number immediately. Despite the appearance, the computer itself is not locked and operating-system controls remain available Netskope also noted similarities with CypherLoc, a scareware campaign Barracuda reported in May. CypherLoc used encrypted code and browser controls to display convincing fake security alerts. Same locker with different skins for Windows (left) and macOS (right) and the black lockout screen (Image Source: Netskope) Staying Safe Anyone who encounters the fake alert should not call the number shown on the screen. Netskope suggests holding down Escape for a few seconds to release the browser from full-screen mode. The tab can then be closed. If the browser remains stuck, Windows users can use Task Manager, while Mac users can use Force Quit. Netskope also advises reopening the browser without restoring the previous session. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts BrowserCybersecurityGoogle AdsMalwareNetskopeScamWindows Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Cyber Attacks Cyber Crime Malware Uiwix, yet another ransomware like WannaCry – only more dangerous In the last few days, the internet has been caught off guard with numerous updates being posted regarding… byJahanzaib Hassan Read More Hacking News Security Even Solar Panels Can Be Hacked Believe it or not, your Solar Panel can be hacked as well — Just like this man who… byRyan De Souza Read More Security SAP NetWeaver Flaw Scores 10.0 Severity as Hackers Deploy Web Shells A critical vulnerability (CVE-2025-31324) in SAP NetWeaver Visual Composer puts systems at risk of full compromise. Learn how… byDeeba Ahmed Read More Security Malware Backdoors in Python and NPM Packages Target Windows and Linux Checkmarx uncovers cross-ecosystem attack: fake Python and NPM packages plant backdoor on Windows and Linux, enabling data theft plus remote control. byDeeba Ahmed

Indicators of Compromise

  • malware — CypherLoc

Entities

Google Ads (product)Netskope (vendor)Microsoft Defender (product)