Google Ads Campaign Spreads Fake Security Alerts That Lock Browsers and Push Malware
A malicious Google Ads campaign is distributing a browser-locking scam kit that displays fake security alerts, aiming to trick users into calling fraudulent support numbers.

A sophisticated Google Ads campaign is actively distributing a browser-locking scam kit that presents users with convincing fake security alerts, designed to coerce them into calling fraudulent support lines. Researchers at Netskope Threat Labs identified this operation, which leverages malicious advertisements to redirect unsuspecting users to cloud-hosted pages that initially mimic legitimate online stores. These pages then dynamically display operating system-specific warnings, aiming to exploit user fear and urgency.
The campaign's stealthy approach begins with a seemingly innocuous loading spinner and an ordinary-looking online store, designed to bypass initial suspicion. Once the user interacts with the page, particularly by moving their mouse, hidden code decrypts a server address and retrieves a tailored version of the locker for Windows or Mac. The fake alert is then constructed directly within the browser's memory, making it difficult for traditional network scanners to detect the malicious payload. If the remote server fails or decryption falters, the storefront remains visible, masking the underlying malicious activity.
From August 31 to September 14, 2026, Netskope observed this scam kit reaching at least 619 organizations across more than 250 ad campaign IDs, appearing on at least 284 legitimate publisher websites. The operation utilized over 457 scam hosts, with traffic records indicating a heavy reliance on paid Google ads rather than organic search results. The malicious ads were served through normal ad inventory on popular sites, demonstrating how threat actors can exploit advertising networks without compromising the publishers themselves.
On Windows, the fake alerts imitate Microsoft Defender scans, displaying layered infection warnings. For Mac users, the campaign uses Apple-themed alerts. Both versions repeatedly display a support number, creating a sense of crisis and presenting a call to the number as the only solution to the supposed problem. The full-screen browser mode, hidden cursor, disabled exit shortcuts, alert sounds, and deliberate browser lag further enhance the illusion of a system compromise.
While the browser itself is not technically locked, the visual and auditory cues are designed to be highly convincing. The warning is purely theatrical, intended to pressure users into taking the next, more dangerous step: contacting the scammers. This could involve paying for nonexistent repairs, disclosing sensitive financial information, or granting remote access to their systems.
Netskope advises users who encounter such fake alerts to avoid calling the displayed number. The recommended mitigation is to press and hold the Escape key for a few seconds to exit full-screen mode, followed by closing the browser tab. If these steps fail, users are advised to use Task Manager on Windows or Force Quit on a Mac to close the browser, then reopen it without restoring the previous session.
The majority of affected organizations were located in the United States (approximately 62%), followed by Japan (16%) and Australia (14%), based on ad-click geography. This campaign highlights a persistent threat where deceptive web pages, even when difficult to exit, are a strong indicator of a scam, especially when they urge immediate contact with a support number.