VYPR
researchPublished Sep 2, 2026· 1 source

Scareware Ads Persist on Google's Transparency Tool Despite Reporting

Researchers developed a tool to identify deceptive scareware ads on Google's Ads Transparency Center, finding that reported malicious ads and domains continue to run.

Researchers from NYU and Radboud University have developed a tool named AdLens capable of identifying deceptive software advertisements within Google's Ads Transparency Center. This initiative, which spanned a year, aimed to analyze the effectiveness of Google's ad moderation policies. The study's findings reveal a persistent issue: even after malicious ads and their associated domains are reported, they continue to operate on Google's platform, underscoring significant challenges in ad enforcement.

The AdLens tool processed approximately 188,000 software-related ad creatives from Google's public archive. It employed a two-stage detection system, beginning with a rapid similarity search to flag potential offenders, followed by analysis from open-source language models to confirm their deceptive nature. This rigorous process identified 238 scareware ads, 3,346 ads making false claims, and 258 ads designed to obscure their origin. Collectively, these problematic ads garnered over 100 million impressions in Europe alone.

The scareware advertisements often employed alarming language, such as "Your phone has been severely damaged by 33 types of viruses" or "Storage Almost Full, Insufficient storage may prevent app installation." One advertiser was found to be running 90 such ads, accumulating over a billion impressions across their catalog. These operations leverage Google's core advertising infrastructure and have been running at scale for extended periods.

Ads making deceptive claims were even more prevalent, promising capabilities like recovering deleted photos or enabling phone location tracking with just a number. The most viewed ad in this category had been active for over two years, amassing 14.5 million impressions. A third category of ads focused on obscuring the advertiser's identity, featuring minimal content and generic buttons or QR codes that led to unidentifiable destinations. One such French ad, with no clear attribution, achieved 1.6 million impressions.

To test Google's response, the researchers reported a sample of the flagged ads using an EU-based account, which provides status updates on reports. The results were inconsistent; while some ads were removed, others were acknowledged as violations but remained live. In one instance, Google stated it could not review a scareware ad that was publicly visible and still accumulating impressions.

Further investigation traced some ad landing pages to malicious domains identified by multiple DNS services, including one linked to the TamperedChef malware campaign. While reporting a single ad associated with this domain led to its removal, 41 other ads pointing to the same domain continued to run. This highlights a systemic issue where individual ad takedowns do not necessarily address the underlying malicious infrastructure.

Ritik Roongta, a researcher at NYU involved in the study, expressed frustration with the lack of response from Google's trust and safety team regarding a more effective reporting mechanism for blanket blocking of malicious URLs. The researchers suggest that blocking by domain rather than individual ads could close these gaps, although they acknowledge the challenge of maintaining updated blocklists due to frequent rotation of registrars and hosting providers by malicious actors.

AdLens's affordability is a key feature, built entirely on open-weight models with minimal operational costs. This accessibility allows smaller organizations, such as newsrooms or regulatory bodies, to conduct similar analyses independently. The researchers believe the pipeline is modular and can be extended to other ad platforms like Meta and Amazon, as well as other content categories, with plans to incorporate video ad analysis in the future. The study's findings raise questions about the efficacy of Google's current ad moderation and enforcement practices.

Synthesized by Vypr AI