Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Google Needs to Strengthen Ad Security After Latest Malvertising Incident

Posted on January 20, 2025January 20, 2025 by Martin Brinkmann

A recent incident has shown another security vulnerability in Google’s advertising platform: advertisers can display URLs of legitimate websites in their ads while redirecting clicks to malicious destinations.

This deceptive practice has recently been exploited in a concerning incident. Here is what happened.

The popular macOS package manager Homebrew became the target of cybercriminals in a sophisticated phishing campaign. Developer Ryan Chenkie discovered a fraudulent website being promoted through Google Ads that impersonated the official Homebrew platform.

The attackers employed a classic typosquatting technique, registering the domain “brewe.sh” to mimic Homebrew’s legitimate domain “brew.sh.”.

The cybercriminals booked ads on Google’s advertising platform to lure unsuspecting users into their trap. While the target URL was different, the ad on Google Search showed the address of the legitimate website to searches.

In other words: A glance at the address would show the correct address to searchers. A click on the ad, however, would load the malicious website instead.

The fraudulent site was professionally designed to appear identical to Homebrew’s official website. However, instead of providing legitimate software, it distributed malware through compromised cURL downloads. According to reports, the malware specifically targeted user passwords.

The main takeaway for users: do not trust the address, title, or ad text that Google displays on Google Search. Better yet, use a content blocker to get rid of these ads entirely.

Google has apparently reacted to this particular ad and plans to “stop similar patterns in the future”.

Closing Words

One of the main problems of advertisement on the Internet is that it is regularly abused by cybercriminals. Even Google, with all its money that it earns from advertising, seems uncapable of putting an end to this abuse.

It is a trust issue and the only way of protection is to use content blockers. The added benefit of this is that users save potentially gigabytes of data each month,, speed up browsing on the Internet and improve your privacy.

This is why my website does not have any ads. You can still support me though, for instance by subscribing to my newsletter here.

Tags: google
Category: Security & Privacy

Post navigation

← Here is how you find out if you can subscribe to YouTube Premium Lite
Firefox 134.0.2 is here with a few non-security corrections →

3 thoughts on “Google Needs to Strengthen Ad Security After Latest Malvertising Incident”

  1. boris says:
    January 20, 2025 at 11:10 am

    Google is obviously leaving humans out of the loop on all ad services. The system just needs few hundreds trained people randomly trying out Google Ad links to pick up all the scams within few days of their launch. I think Google can afford it but chooses not too since there are no penalties for bad business if you are almost monopolist.

    Reply
  2. Tom Hawack says:
    January 20, 2025 at 11:19 am

    The main takeaway for users is as described in the article is imperative. A OS and browsers which are undoubtedly its most used component, just cannot be ran out of the box.

    Generally speaking and IMO advertisement — unless should it be strictly controlled by advertisement vectors, which has never been done up to now — is incompatible with privacy but as well with security concerns. Ads and a secure digital environment are incompatible.

    Meanwhile the first company to tie them is Google while Google stands a pole position in the digital tech area. A challenge for the mental sanity of those who rely on this company to travel in the Wild Wild Web.

    Follow the article’s advice, both imperative :
    – do not trust the address, title, or ad text that Google displays on Google Search.
    – use a content blocker to get rid of these ads entirely.

    Follow a wise recommendation : avoid to the maximum extent GAFAM companies, that means avoid their services of course (alternatives exist for most) and use blacklists, dedicated add-ons & userscripts to to bypass their intrusions, those which occur even with a non logged-in account, those which occur even with no account : the number of third-party connections to Google servers (as well as to other major companies) is absolutely amazing, but Google remains leader of the band.

    Reply
  3. boris says:
    January 20, 2025 at 1:32 pm

    “– do not trust the address, title, or ad text that Google displays on Google Search.”

    That has being true for quite a while. Better choice: use Google search only as backup search engine. Choose one of the smaller, relatively independent search engines as your primary search engine and use Google only if some function is not available, or if you cannot find the answer. Yes, sometimes searches can take longer (not always), but risk will be greatly diminished.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • May 18, 2025 by Martin Brinkmann Netflix to use AI "to serve the right ad to the right member at the right time"
  • May 17, 2025 by Martin Brinkmann Windows 10 update may cause another Bitlocker recovery reboot issue
  • May 15, 2025 by Martin Brinkmann Chrome 136 update patches security issue that is exploited in the wild
  • May 13, 2025 by Martin Brinkmann Firefox 138.0.3 fixes two crashes and some other issues
  • May 12, 2025 by Martin Brinkmann Microsoft 365: Windows 10 continues to be supported, at least somewhat

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews