Google Ads became a malware distribution channel
Malvertising turns Google's top search ad into a malware delivery channel. How the attack works, why review misses it, and the steps that stop it.
In October 2023, a Google search for KeePass, the open-source password manager, put a paid ad at the very top of the page. The display URL read like the real site. One character was a Punycode lookalike, a k with a small mark under it, so the true domain was xn—eepass-vbb.info rather than keepass.info. The site behind the ad served a malware loader instead of a password manager. Malwarebytes documented the campaign. Google pulled the ad. By then it had run at the top of the page and collected clicks from people who did everything they were taught to do.
That is malvertising, and it works by inverting the one signal users trust most: position at the top of the results.
I track these campaigns as a systems problem, not a morality tale. The point is not that criminals lie. Google Ads has become one of the most efficient malware distribution channels ever built, and the reasons are structural.
The channel does most of the work
A search ad for software borrows Google’s credibility and rents the most valuable space on the internet: the line above the result you were already looking for. Someone who types “Notepad++ download” or “Slack for Windows” has already decided to install software. They are in a downloading frame of mind. The sponsored result sits above the organic link, wears the same blue-link format, and carries an implicit endorsement. It appeared on Google. It shows the brand name. So the user reads it as vetted.
Classic phishing has to manufacture desire and urgency from nothing. Malvertising skips that step. It intercepts intent that already exists. The attacker does not persuade you to want the software. You brought the wanting with you.
That inversion is why a clone of a legitimate installer, delivered through a paid ad, converts better than almost any phishing email. The user is not being ambushed. They are being served, at the exact moment they asked to be.
The campaigns are documented, not hypothetical
Through 2022 and 2023, security vendors tracked a sustained wave of Google Ads impersonating popular software. The impersonated brands included Grammarly, Slack, Zoom, Notion, OBS, MSI Afterburner, Blender, AnyDesk, and Notepad++. In 2024 the same pattern hit the Arc browser within weeks of its Windows launch. The lookalike sites copied the real product pages pixel for pixel and offered a download that installed a stealer or a loader alongside, or instead of, the real program.
The payloads were commodity crime tools: Rhadamanthys, RedLine, Vidar, and Aurora for stealing credentials and crypto wallets, plus loaders like BatLoader, IcedID, and Bumblebee that pull down whatever comes next, often ransomware. Researchers repeatedly traced initial corporate compromises back to an employee who installed a trojanized tool from a search ad.
This is documented enough that the FBI issued a public advisory about it in December 2022, warning that criminals were buying search ads that impersonate brands to defraud users, and recommending ad blockers as a defense. When a federal agency tells the public to run an ad blocker for safety, the distribution channel has a problem.
Follow one click to the breach
Trace one install through to the damage. An IT contractor needs AnyDesk to support a client, searches for it, and clicks the top result, an ad. The page is a faithful copy of the real one. The download runs, the remote-desktop tool works exactly as expected, and bundled alongside it a loader quietly installs. Nothing looks wrong. Days later, credentials harvested from that machine, including the saved logins for the client networks the contractor supports, show up for sale. Weeks after that, a ransomware crew that bought the access walks into one of those networks through a legitimate remote-access account. The victim organization never searched for anything. Their exposure began with a support technician clicking a sponsored link.
That chain is why malvertising matters more than its per-victim numbers suggest. One bad click on a machine with reach becomes a breach for everyone that machine can touch.
The review gap is a scale problem
Google is not asleep. Its own 2023 Ads Safety Report says it removed billions of ads and suspended more than twelve million advertiser accounts. Those numbers describe the size of the fight, not a victory. Review at that scale runs on automation, and automation can be gamed by anyone who understands what the reviewer sees.
The core trick is old and simple in concept: show one thing to Google’s crawler and another to the human who clicks. Attackers point the ad at a clean, benign page when the request looks like a review bot, and swap in the malicious download when the request looks like a real user in the right country on the right browser. The security industry calls this cloaking. Combine it with freshly registered lookalike domains and disposable, sometimes stolen, advertiser accounts, and each takedown removes one instance of something the operator can respawn in hours.
The asymmetry runs the wrong way for defenders. A security team blocks a malicious domain after it is reported. The advertiser has already rotated to a new domain and a new account. Reporting is retrospective. The ad auction is live.
The loophole Google will not close
There is also an incentive conflict Google rarely names. Bidding on a brand keyword you do not own is allowed by policy, which is how competitors advertise against each other and how comparison sites survive. That same rule lets an attacker legitimately buy the word “KeePass” and pair it with a lookalike domain. The permission is a feature for advertisers and a loophole for criminals, and closing it would cost Google a real slice of ad revenue. So the platform fights the symptom, malicious creative and bad accounts, rather than the structure that makes brand impersonation buyable in the first place. That is why the takedowns never end and the campaigns keep returning under new names.
The economics are lopsided
A click on a niche software keyword costs pennies to a few dollars. A single successful install can hand over a corporate VPN credential, a browser full of saved passwords, or a crypto wallet worth thousands. The attacker does not need a high conversion rate. They need cheap, targeted traffic from people already trying to install software, and the ad auction sells exactly that.
Stealer logs feed a second market. Access brokers collect credentials harvested from these installs and sell them to ransomware crews, who turn one employee’s bad download into a network-wide extortion event weeks later. The person who bought the ad and the person who detonates the ransomware are often not the same people. The ad was step one in a supply chain.
What actually protects you
Treat sponsored results as unverified. When you want software, do not click the ad. Scroll past it to the organic result, or better, type the vendor’s domain yourself, or go through the project’s official GitHub or documentation page. The extra three seconds removes the entire attack surface.
Check the domain before you download, character by character, not at a glance. Punycode and hyphenated lookalikes are built to survive a quick read. A password manager helps here in a way most people miss: it will not autofill your credentials on a lookalike domain, because the domain does not match. If your manager stays silent on a login page you expected it to fill, the page is not the site you think it is.
Verify the installer when the project publishes a way to. Signed binaries, published hashes, and checksums exist so you can confirm you got the real file. Most people skip this. For anything with access to money or a corporate network, it is worth the minute.
What actually protects an organization
Run DNS filtering that blocks newly registered domains, since malvertising leans on domains that are days old. Deploy a browser-level ad blocker like uBlock Origin as a managed policy; the FBI’s own advice to use one applies at the fleet level, and it removes the malicious ad before a user can misread it. Pair that with endpoint detection and, where you can tolerate it, application allow-listing, so an unsigned installer from a random domain cannot execute even if someone downloads it.
Then train for the specific tell. Most security awareness training still centers on email. The lesson employees actually need is narrower and more useful: the word “Sponsored” is a purchase, not an endorsement, and downloading software from a search ad is the risky path. Say that plainly, show them a real cloned page, and you have covered the vector most programs ignore.
The awareness problem underneath all of this
The deeper issue is that “Sponsored” reads as “safe” to almost everyone outside security. Twenty years of Google conditioning taught people that the top of the results page is the authoritative answer. Attackers did not break that trust. They bought it, at auction, by the click.
No download checklist fixes a trust signal that the platform itself sells to the highest bidder. Until the label above the real result stops reading as an endorsement, the most effective advice stays the least intuitive: the ad at the top of your software search is the one link on the page you should not click.
#ad Contains an affiliate link.
Keep Reading
malvertisingRanking is not vetting
Attackers buy top Google Ads placement and use cloaking to deliver trojanized installers; ad review validates the submission, not the file you download.
zero-clickZero-click chains broke the user-in-the-loop model
Zero-click malware does not need user action. It needs a reachable parser. What fails, why it fails, and what must be true.
RustMicrosoft's new default is Rust
Microsoft made Rust a tier-1 language because memory-safety bugs drove ~70% of its yearly security patches. Here is what the shift means.
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.