University researchers found large numbers of deceptive “software” ads (including scareware) running through Google’s ad system, generating over 100 million impressions in Europe. They reported some ads via Google’s “Report this ad” flow, but several ads were acknowledged as policy violations and still stayed live, including multiple ads linked to the same malicious domain.
How the attack worked
Researchers mined Google's Ads Transparency Center and identified deceptive software ads at scale, including 238 scareware ads and 3,346 ads making false claims. The flagged ads collectively received well over 100 million ad impressions in Europe alone. The scareware examples used alarming device-infection or storage warnings, such as claims that a phone had been damaged by dozens of viruses, designed to pressure users into clicking or installing a supposed fix. Other ads promised impossible services, like recovering photos deleted years ago or letting a stranger track anyone's phone location just by entering a number. A third category used minimal-content creatives, such as a bare button reading Continue or an unexplained QR code, to obscure who was behind the ad and where it would lead.
Why it succeeded
These ads worked because they exploited trust in a major, widely used advertising platform. Landing pages were linked to malicious domains flagged by multiple protective DNS services, including one associated with the TamperedChef malware campaign. Even after researchers reported ads through Google's Report this ad flow, some were removed, but others were acknowledged as violations and stayed live anyway. Removing a single ad also did not stop the broader campaign: other ads pointing at the same domain kept running, meaning users remained exposed even after individual complaints were resolved.
What to watch for
- Urgent, alarming messages about viruses or storage problems arriving through an ad rather than a device's trusted security tools or app store
- Offers that sound too good to be true, such as recovering long-deleted photos or tracking a phone using only a number
- Ads with almost no information about the advertiser, product, or purpose, including generic Continue buttons or unexplained QR codes
- Ads that have been running for a long time and accumulated large view counts, which does not indicate legitimacy
How to build resistance
Treat alarming device warnings delivered via ads as suspicious and close the page rather than clicking through; use trusted device settings or app store tools to check for real issues. Be skeptical of any ad promising impossible capabilities, and avoid entering personal data such as phone numbers into unfamiliar landing pages. Do not assume that a platform's ad reporting and removal process fully protects users, since a reported ad or its underlying domain may keep running. Finally, be cautious of ads that hide who is behind them, since a lack of clear company or product information is itself a red flag worth treating as a signal to disengage.
Key findings
- Researchers mined Google’s Ads Transparency Center and identified deceptive ads at scale, including 238 scareware ads and 3,346 ads making false claims.
- The flagged ads collectively received “well over 100 million ad impressions in Europe alone.”
- The scareware ads used alarming device-infection/storage warnings designed to pressure users into clicking or installing something.
- When researchers reported ads through “Report this ad,” some were removed, but others were “acknowledged as violations and stayed live anyway.”
- Landing pages were linked to “malicious domains flagged by multiple protective DNS services,” including one associated with the “TamperedChef” malware campaign.
- Removing one ad did not stop other ads pointing to the same domain: “The other 41 ads pointing at the same domain kept running.”
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Finance, HR, IT helpdesk/service desk, Security awareness training audience.
- Affected industries: All industries (general end users exposed to web ads), Information/Media (online advertising platforms), Consumer technology/mobile users.
- Attack channels: website.
- Impersonated: A phone security scanner/antivirus or system alert, A ‘data recovery’ or ‘phone tracking’ service provider, Unclear/undisclosed (ad hides who is behind it).
Red flags to watch for
- Overly alarming language and specific-sounding numbers (“33 types of viruses”) designed to panic the user
- Unexpected security warning arriving via an ad rather than the device’s trusted security/app store
- Pressure implied by urgent damage/blocked functionality claims
- Too-good-to-be-true promises (recovering long-deleted photos; tracking anyone with just a number)
- Vague advertiser identity or unclear business details
- Invasive request for personal data (phone number/location-related info)
- Ad contains almost no information about the company, product, or purpose
- Generic button-only creative (“Continue”) that hides the destination
- QR code in an ad with no clear brand or explanation
Frequently asked questions
What is scareware in the context of these Google ads?
Scareware ads use alarming device-infection or storage warnings, such as claims a phone has been damaged by dozens of viruses, to pressure users into clicking or installing something.
Does reporting a bad ad to Google stop it from running?
Not always. Researchers found that reporting a bad ad to Google doesn't mean the ad, or the domain behind it, stops running, and some ads were acknowledged as violations but stayed live anyway.
What other tactics did these deceptive ads use besides scareware?
Some ads promised to recover photos deleted years ago or let a stranger track anyone's phone location just by entering a number, while others used bare 'Continue' buttons or QR codes to hide who was behind the ad.
How many impressions did these deceptive ads generate?
Researchers found that flagged ads, including 238 scareware ads and 3,346 ads making false claims, collectively received well over 100 million ad impressions in Europe alone.
Read the video transcript
You’re scrolling a news site and a banner screams, “Your phone has been severely damaged by 33 types of viruses.” Researchers found hundreds of these scareware ads running through Google’s main ad system, over 100 million impressions, even after some were reported and confirmed as policy violations. Some ads push fake virus fixes. Others promise to recover photos deleted years ago or track anyone’s phone just by entering a number. Behind them: malicious domains and long‑running scam campaigns. If a web ad claims your device is infected or offers impossible tracking, don’t click it, close the page and use your phone’s own security or app store tools instead.