Infrastructure·
Google Ads Weaponized in Tech Support Scams That Freeze Devices
Malicious Google Ads are masquerading as system alerts that lock browsers and demand victims call a fake support line, exploiting both user naivety and infrastructure trust.

The latest wave of malicious Google Ads pretends to be a system alert that locks the browser, hides the address bar, and disables common exit keys. The fake warning fills the entire display, mimics real infection signs, and pressures the user to call a bogus support line.
Security firm Netskope recorded clicks from 619 organizations between August 31 and September 14, with 62 % located in the United States, followed by Japan and Australia. More than 250 distinct Google Ads campaign IDs were observed across 284 legitimate publisher sites, indicating a broad distribution network that leverages high‑traffic pages such as maps, weather, and real‑estate portals.
The payload is deliberately stealthy: the malicious code is encrypted in memory, only decrypted when executed, and the browser UI is replaced with a full‑screen locker that blocks mouse movement, escape, and other termination shortcuts. These techniques evade many endpoint protection solutions and can slip past standard ad filtering mechanisms.
For AI and GPU‑accelerated cloud services, the impact extends beyond individual workstations. Compromised browsers can expose API keys, model checkpoints, and training data to remote attackers, jeopardizing the integrity of AI pipelines. Strengthening ad verification, enforcing strict endpoint controls, and monitoring traffic anomalies are essential to protect the underlying infrastructure that powers modern AI workloads.
- aigpu
- ai gpu
- ai gpu cloud
- aigpu dubai
- ai security
- cloud infrastructure
- tech support scam
- google ads
- cybersecurity
- gpu
By AiGpu Editorial · Editorial rewrite based on public reporting (Ars Technica)
← All articles