Nati Tal on Phishing Scams Targeting E-Commerce via Google Ads
Nati Tal, head of research for Guardio, explains how a new phishing scam targeting e-commerce companies uses ads surfaced by Google to inject malware into content to steal data.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nati Tal, who's head of research for Guardia, and we're talking about a new novel type of attack that's affecting e-commerce companies and that are making use of Google ad search capabilities.
But Naty will explain that in better detail than I will. Naty, welcome to the show. Hey, thank you.
Nice to be here. So walk us through this attack vector a little bit 'cause it seems like it's a little something new and different, and of course the bad guys are always changing their tactics and techniques, but what's going on here? Well, it's huge, huge story, ma mainly focusing on sponsor results on Google, but not only, so let's start with a simple example.
Um, you search for an application, you want to install something that you're used to, that's the, let's say Slack or some something else, a notion and so on. And you are used to search on Google and click on the first result as always. And sometimes it's a sponsored result.
Sometimes it's the real SEO style result. Uh, but you are kind of used to that. And you also want to, to imagine that your, the results from Google are legit.
So you click on the first one and you go to a site that looks and feels like Slack, for example, and you install the application and everything sounds legit and looks great, but in the meantime you got Slack installed, but also a small segment of an application that is, was installed with it, which is a stealer. Uh, and this kind of campaign is targeting all users, all people, and is more common for people that are looking for those kinds of applications, let's say Slack, meaning that those user, those computers are in most cases part of a company or an enterprise. And eventually the data that is being stolen and is precious and valuable.
And from that moment on, threat actors have full access to that company's network. And this kind of example is something that we see in the past year. And so even more, uh, and the more, the more and more you, so you see those kinds of campaigns in Google ads, for example.
Yeah, there are also other vectors like ads on Facebook and social and so on. But in Google, Google specifically, it's actually quite too easy to create a campaign and name it after another brand like Notion Slack or any other kind of, uh, software that you are used to, to install target specific audiences because this is what Google Ads does. Target specific countries, cities type of people, high tech workers and so on, and get your malicious software installed exactly where you wanted it to.
You see that a lot lately. Yeah, unfortunately. How difficult or easy is it for cyber criminals to kind of create and launch this type of attack and how prevalent is it gonna be?
Well, at first when we saw that, like a year ago, uh, we tried to understand how exactly it passed all the, the testing and authentication that Google does for the advertisers. Uh, and what we realized is that it's not always this straightforward, meaning you are not going and advertising a software that is called after another one's brand and, and use domains that are similar in a, in a sense like Slack with two C or stuff like that. Or we also talk about, uh, using different types of encoding instead of general letters.
So it looks like it's the real domain, but it's not. But in many cases, they're using other kinds of approach to not, or not only, um, abuse the ad network itself and to target us, but also in a sense target Google and try to mitigate their, uh, testing and their authentication. And they do that in many different ways.
One of those is what we call cloaking. They create a campaign for some basic website, some standard service. We saw different examples for plumbers in Minnesota and stuff like that.
They create a website that looks legit of some kind of a plumber. Mostly by the way, AI generated just one click and you have a website to advertise it. But once the campaign is live and once it is going and running and you gain the reputation of Google, in this case, they just switch it to another website.
And once you go to this website form a click on any kind of sponsored result, you end up in a different website. The Target website, the malicious website in this case, uh, this way moderators at Google can see it if they go to the CRL, the CL legit website. But once it a, it is active and ongoing, victims of this campaign are going to their malicious website.
Um, so this is one way to do that. But there are others as well. Uh, one, one example we saw in the last few days was for another service, uh, called Triple Way.
And when you search, even today by the way, you search for Triple Whale on Google, you get the first results, poned sponsored result for this site, and then another one sponsored for the same website, same service. The first one looks exactly like the second one, but the advertiser is different. One is actually the company behind the wave.
And the first one is a different company. Something, I don't remember exactly the name from a Chinese or Taiwan Taiwanian company that does that for other brands as well. com, but the T is a bit, if you look closely, it's a bit different.
It's a t form, another language, another encoding that looks exactly like the original with a different, with like small line on top of that. Uh, and this is a different domain, different website, and it goes to a different target in the end, not the actual triple way. Uh, and and for some reason it's first in the results in Google.
And the reason for that is because it's a market. Advertising is a market. You place more money for this ad placement, you will be first and you, and you, if you buy this keyword triple way for less money, you will be second or not even there at all.
Uh, and here comes also the, the, the, the way that Google does this business, after all ad ad networks like Google, in this case, it's like the main business. It's more than 50% of their annual revenue, if not even more, I think. And they're obligated for the advertisers.
They are their users, their customers. And it's not easy for them to just take down this kind of advertising because again, they're legit advertisers that do this business and the entire ecosystem is based on this. And it's a bit problematic for them to check each and every advertiser and also make sure that there are no such abuses of their network.
I I'm not saying that they are not obligated to do that or have the responsibility to do that, but I can realize why it's hard for them to do that as well. So who's responsible for mitigating all this? Is it the e-commerce companies that have gotta go look for all this stuff or is it Google or is there some sort of like shared responsibility model we need to navigate?
Yeah, Yeah. And this is exactly what also the threat actors are abusing as well. Who is responsible.
And because the chain is so long and you have the, have Google and the advertisers and the companies themself and and other ad companies and creative companies, they in the middle of this chain. So who is responsible at the end to all this malicious advertising, not only in Google as well. Uh, and this is one, one, I don't know like the main, uh, reason why it's so easy.
So it's quite easy today to use advertising to propagate malicious content because this ecosystem is so complicated and in, you know, in a, in an in the, in the world where you wanted, everything will be safe and everything will be great. You could say that, okay, Google, you, you cannot do that. You can't give a permission for some, someone with malicious intents to advertise something like that on the top list of your search results.
After all people have, you have the reputation of Google of being the gateway for the internet. People are used to just click on something or look for something and click on the first one. They're getting the search results.
You can't break this reputation, it's your obligation to do that. So this is Google, but again, there are different elements that can also harm them in doing so. In this case, they will harm main revenue vector.
Uh, uh, and on the second step of that, those are the users that actually use Google and want to give them the, the reputation they deserve in this case and use in the internet really without worrying about every click they do. So you have Google or any other gateway or ad network that have the responsibility to fix that or be more in focus for those kinds of attempts. 'cause they're all over the place.
It's easy for me just to create one simple search and I found at least three post advertiser on, on the Google network. So I guess it's easier for them to do that as well. And there are also the companies that advertise themself, let's say triple one in this case, they need to realize they need also to check out Dell Posture is on the internet, relates to those kinds of false advertising.
Not only using their brand name in efficient page, but also in search results. Something that I'm not sure everybody's looking for as well. And Google by the way, provides those kinds of tools to search for advertisers and advertisements and like with full visibility to any kind of advertising.
So just as, as a company look for others that try to abuse your brand in this vector as well. Mm-hmm. And of course our US users, we need to realize it's not that simple just to click search something and, and click on that.
We need to be more cautious in what we are doing. It almost seems like this is a variation of an attack where, um, you know, they're basically changing the name of their company by one letter. So you don't realize that you're clicking on something and this kind of feels like the next iteration of those types of attacks.
So are we gonna see a lot more of these types of things? Yes, yes, unfortunately. Uh, and, and we see brand abuse being more and more easy for threat actors in, in a means of buying those different types of new TLD domains that can look and feel like the real website or the real brand.
We can see more and more vectors for propagation like social media and Google search and Google Edwards. And, and you, you, you, you start to realize that everywhere where you get content in today's internet is a place where threat actors will try to find the content you are looking for first and be there first. Be the first one in the search resort, be the first one in your social feed because this is where you are looking for content and they want you to reach them.
So when we get to a point where people just won't click on anything 'cause they won't trust it and you know, the whole system is based on that trust factor. So is this kinda just, you know, the beginning of something where people might decide that, well, I'm just not gonna pay any attention to any advertising at all. 'cause it's might be more trouble than it's worth?
Yes and no. And of course I don't want it to be yes, because if we break this model of advertising, we want to have internet, we want to have all this, the good stuff, we have the internet because eventually this entire ecosystem is based on advertising and we get free products because we are the product. So, and we love that eventually because we use those products, we are so used for to those products and we dissolve those products.
So we just need to be more cautious and more, uh, and to realize how threat actors work and to be more aware of those different types of, of attempts and vectors and even more complex vectors because awareness is like the first thing we need to do. And if we are more aware, we, it'll be like easier for us to skip over those kinds of attempts. And again, it's not 100% word proof.
You can be aware on and on everything all the time. And I'm saying that as well as like, like one that have more than 20 years of, of experience in cybersecurity. I, I talk to about myself, I can be 100% safe just by being aware.
Uh, and I can also sleep and click on something that I didn't realize because, you know, the world is so crazy and everything is going on at the same time. You get like handle notifications a minute in your phone and something can slip, slip over this kind of awareness. Uh, this is why we really need different tools, automated tools that will help us, uh, if it's a robust was in protection or any kind of other protection.
Just like enterprises have all the cybersecurity tools, you also need one as their person, as a regular person. Oh, cool. Hey folks, you heard in here the bad guys.
They're just getting clever all the time and they're really getting into the content. It's not just kind of the the old style attacks that you may have seen in the past. And if you're an e-commerce vendor, you gotta protect your brand because well, Google will help, but they can't do everything themselves.
Hey, Nadi, thanks for being on the show. Thank you. Thank you.
All right. And back to you guys in the studio.