Search engines have become embedded into the way users find information, with internet giant Google processing over 84.2bn searches per day worldwide.
Fake advertisements that appear within a user’s search results are increasingly being used to entice unsuspecting users to phishing websites and malware downloads, finds BlueVoyant.
The Growing Threat of Search Engine Ads report detected a 28% rise in malicious ads with 70% of ad-related websites found to be non-lookalike domains with intent to deceive.
This is an alarming figure which can somewhat be attributed to the ease of access to self-service advertising tools and a vast readily available user base.
An elusive and often hard to detect phishing trend
Most search engine ads appear above organic results and have a title, description, and a link.
According to the findings, fake ads are cleverly designed to look almost indistinguishable from real ones, making it easy for users to click and unwillingly put their personal, financial, and corporate information at risk.
Creators of these ads specifically target users with a set of criteria to maximise the chances of them appearing in top search results and minimise the chances of them being caught out.
For example, keywords must be matched exactly during the search query or the ad won’t be shown. An audience’s time-zone and device can also be tailored which then further limits the ads exposure to security bots and threat detection software.
Evasion methods such as IP blocklisting or redirection make fake ads even trickier to detect. The report uncovered instances where a unique session cookie is created once an ad is clicked and the phishing content will not be displayed without it.
Recommended reading
- Threat Actors Hit GitHub Search With Malware Scheme
- 53% of Malware-infected Devices are Corporate
- Watch Out for Fraudulent Bank Websites, Says Which?
So how can organisations mitigate malicious search engine ads?
With easy-to-use interfaces and high volume of users, it was only a matter of time before Ads were used to perform malicious attacks.
The report made a variety of recommendations to minimise risk such as regular monitoring, raising awareness to staff and customers, and installing sophisticated phishing detection software.





