RC RANDOM CHAOS

Ranking is not vetting

Attackers buy top Google Ads placement and use cloaking to deliver trojanized installers; ad review validates the submission, not the file you download.

· 7 min read
Ranking is not vetting

The paid result at the top of a Google search page is attacker-controlled content. It is bought, not earned. The position it occupies says nothing about the safety of the software behind it. The users who click it are trusting placement, and placement is a purchase.

The visible interface presents the sponsored listing with the same weight as an organic result. Real product name. A display URL that reads as official. A description that matches exactly what the user typed. The observable behavior of that listing is indistinguishable from the legitimate vendor’s until the download runs. That gap is the entire operation. It is not a flaw in the software the user wanted. It is a flaw in the thing they trusted to reach it.

When I bought ads against software names, I was not attacking the vendor. I was renting the top of the funnel. The keyword was the target, not the product. Anyone searching a well known tool by name had already decided to install something. The only job left was to be the first result they clicked and to look correct while they did it. Search intent did the recruiting. The ad only had to intercept it.

Most people operate on an assumption that the search ranking is a safety control. The belief runs that the platform surfaces trustworthy results first, that the top position signals legitimacy, that a sponsored tag is an endorsement rather than a paid slot. None of that is enforced. Ranking is not vetting. The order of results is a commercial output, and the top of that output is for sale.

What the user can actually observe reinforces the wrong conclusion. The listing shows the genuine product name. The domain string reads as the official one. The landing page reproduces the vendor’s branding, layout, and download button. The connection carries a padlock because the attacker’s domain also holds a valid certificate. HTTPS confirms the session is encrypted. It confirms nothing about who is on the other end. Every visible signal the user is trained to check returns green.

The deeper assumption is that the ad platform’s review means the destination is safe. It does not. Ad review validates policy compliance against the material it is shown at submission time. Approval of an advertisement is not validation of the file a user later downloads. Those are two different objects checked at two different moments. If anyone assumed a control sat between the click and the payload, that control was not confirmed to exist there. In practice, it did not.

The mechanism turns on a single fact. Trust is placed once, at the moment of the click, and it is never re-validated after. The boundary that matters is identity: which domain served the page, which publisher owns it, which binary was delivered. The user never checks that boundary because the interface collapses it into one trusted-looking line. Continuous validation is the requirement. A one-time visual check at the top of the funnel is not validation.

The review process is bypassed through cloaking. The infrastructure serves different content depending on who requests it. The reviewer and the automated crawler receive a clean, compliant page. The targeted user, filtered by geography, device, and referrer, receives the malicious download. The same advertisement URL resolves to two different experiences. The control that was supposed to inspect the destination only ever saw the version that was never delivered to a victim. A control that inspects a different input than the one users receive is not enforcing anything. It is theater with a log entry.

The delivery is built to preserve function. The display URL and the true destination are separate fields, so a listing can read as the official domain while pointing at a lookalike. The download is a trojanized installer. It runs, the expected application opens, and the user gets exactly what they searched for while the payload executes in the same context. Nothing observable breaks. Nothing prompts suspicion. The success condition of the attack is that the user’s experience matches their expectation precisely. What changed is cost and speed. The attacker no longer waits to rank. The platform’s trust is borrowed, the boundary is bought and displayed, and the price is a single click.

The control failed at a single seam. The object the platform inspected and the object the user received were never the same object. Ad review ran against the material submitted at approval time. The download ran against whatever the infrastructure served at request time. Those are two separate artifacts checked, or not checked, at two separate moments. The approval attaches to the first. The victim receives the second. Nothing observable binds one to the other.

The identity boundary is where the seam sits. The display URL and the true destination are independent fields. The string the user reads is a label. The domain that answers the request is the authority. The interface presents the label as if it were the authority, and there is no enforced binding between them. A listing can read as the official domain while resolving to a lookalike, because the field that displays identity and the field that determines identity are not the same field. The user validates the label. The label validates nothing.

Cloaking closes the loop by controlling which artifact each requester sees. The reviewer and the automated crawler receive the compliant page. The targeted user, filtered by geography, device, and referrer, receives the malicious download. The same advertisement URL resolves to two experiences. The control inspected an input that was never delivered to a victim. A control that inspects a different input than the one users receive is not enforcing a boundary. It is producing a record. The trojanized installer completes the sequence in the user’s own execution context. The expected application opens. The payload runs alongside it. No observable signal breaks, because the success condition of the delivery is that the user’s experience matches the expectation exactly.

The pattern is not specific to search advertising. It is the general failure of any control that validates one artifact while the system delivers another. When the inspected object and the delivered object are decoupled, the inspection describes the inspected object only. It says nothing about what reaches the user. Approval at submission time is a statement about submission time. Treating it as a statement about delivery is the error, and the error is structural, not situational.

The same mechanism appears anywhere a display field is separated from a destination field and the display field is treated as identity. The user is trained to read the visible string and to stop there. The visible string is decorative with respect to where the request actually goes. Every signal the user is taught to check, the product name, the domain text, the padlock, resolves against the presentation layer and not against the serving party. HTTPS confirms the channel is encrypted. It does not name who holds the other end. A valid certificate on the attacker’s domain returns the same green state as a valid certificate on the vendor’s. The check passes on both. The check was never measuring what the user believed it measured.

Cloaking generalizes the same way. Any validation that runs against a requester the attacker can identify is a validation the attacker can serve around. If the reviewing party is distinguishable by geography, device, or referrer, the reviewing party can be handed a different reality than the target. The condition that makes this possible is that trust is assigned once, at a single point, and never revalidated against what is actually delivered. Wherever trust is placed one time at the top of a funnel and carried forward without recheck, the same interception is available. The specific channel is incidental. The decoupling is the pattern.

Identity is the boundary, and the boundary was never checked. The domain that served the page, the publisher that owns it, and the binary that was delivered are the only facts that describe safety here. None of them are visible in the listing the user acts on. A control that cannot see the delivered artifact cannot govern it. Ad review, as observed, governs submissions. It does not govern downloads. State it as what it is. It is not a control over the file. It was not confirmed to sit between the click and the payload. In practice it did not.

What must now be true is narrow. Validation has to run against the artifact the user actually receives, at the point of delivery, bound to the identity that served it. A check performed on a different input, at a different time, against a different requester is not that. The display layer is not a trust anchor. The click is not a validation event. Placement is a purchase and confirms nothing about the party behind it. Any process that assigns trust to position, to a familiar name, or to an encrypted channel is assigning trust to fields the attacker controls or rents.

If a system permits the inspected object and the delivered object to differ, that difference will be used. It requires no flaw in the software the user wanted and no compromise of the vendor. It requires only the seam the platform already ships. The boundary that matters is the serving identity, and until that identity is validated against what is delivered rather than what is displayed, the top of the search page remains attacker-controlled content wearing a trusted label. Treat the sponsored result as unverified origin until the serving domain and the delivered binary are confirmed. Everything above that line is presentation.

Share

Keep Reading

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.