Cybersecurity
Malvertising: How Scam Search Ads Steal Logins and Spread Malware
Scammers buy search ads on trusted brand and software names, so the top Google result is not always the real one. Here is how to spot it and stay safe.
Scammers buy ads on Google and other search engines using the names of trusted brands and software, so their fake site shows up at the very top, above the real one. Click it, and you can land on a page built to steal your login or install malware. Skipping the sponsored results and going to a site you already trust closes off this specific trick, though it is not the only way a fake site can reach you, as the sections below explain.
When you search Google for a program to download or a website to log into, the first thing you usually see is an ad. It sits at the top, marked "Sponsored," and some people click it without a second thought, treating it as the top result they were looking for.
Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it is the official page.
How the Scam Works
The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right.
When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks them to log in and hands the username and password straight to the scammer. Other times it offers the software they were after, and the download installs malware instead of the real program.
Why These Ads Are So Easy to Fall For
These ads are convincing for a few reasons. They sit above the real result, so they are the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they do not feel as suspicious as a random email or text would.
Attackers have also gotten good at hiding from the checks meant to stop them. A pattern documented by BleepingComputer involved scam search ads impersonating well known free software, including VLC, 7-Zip, and CCleaner, that led to downloads carrying credential-stealing malware. Reporting on similar campaigns has described attackers showing a clean, harmless page to ad reviewers while routing everyone else to the malicious one, which is part of why a "Sponsored" label passing review is not proof the destination is safe.
How Common Is This?
Malvertising is a large enough problem that Google runs enforcement at massive scale to fight it. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion ads that broke its rules across all of its advertising products, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams of every kind over the year, not fake-software or fake-login ads alone. Google also pointed to AI as a factor letting bad actors generate deceptive ads faster and at greater scale. The scam search ads described above, the ones impersonating specific software brands, are a documented, recurring pattern within that broader enforcement effort, not a one-time event.
What This Means for Your Business
For a business, the risk shows up in two everyday situations: downloading software, and logging in.
When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser.
When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type a username and password straight into a fake page.
In both cases, the underlying problem is information-stealing malware or a straight credential capture. If what was stolen is a password, phishing-resistant multi-factor authentication is one of the strongest remaining barriers between that password and real account access. But if the malware also stole a live browser cookie or session token, that barrier is already behind the attacker: a session token represents a login that has already cleared MFA, and replaying it does not trigger another MFA challenge. That is a separate problem that MFA alone does not solve, and it is why revoking active sessions matters as much as changing the password once a device has been compromised.
How to Protect Your Team
Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results.
Do not download software from an ad. Type the maker's web address yourself, or search and confirm the result is the vendor's own domain before downloading. Attackers also use SEO tricks to push lookalike sites into the normal, non-ad results, so a result appearing there is not by itself proof it is official; when in doubt, use a bookmark you saved from a page you already trusted.
Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time.
Keep devices and browsers updated. Automatic updates close the exploit-based attacks that rely on an outdated browser or operating system. They do not stop a program someone deliberately downloaded and ran, so endpoint protection, application controls, and limiting who has permission to install software matter just as much for that path.
Tell your team this is a thing. Most people have no idea the top result can be a trap, and knowing it lowers the odds they click it, even though a convincing enough fake can still catch someone who knows better. Pair that awareness with technical backstops like DNS or web filtering and endpoint protection, so one missed click does not depend on catching everyone every time.
What to Do if It Already Happened
What matters next depends on what actually happened after the click.
- 1. Only visited the page, entered and downloaded nothing. Close it. Still check the device for anything unexpected, an unrequested download, a security warning, or unusual behavior, since simply loading a malicious page can compromise an unpatched browser or operating system with no further action from the person who clicked. Treat a device that was behind on updates, or anything that looks off, the same as a download below and have IT check it.
- 2. Downloaded a file but have not run it. Do not open it. Leave it in place, tell IT, and have them quarantine or remove it and confirm it was never executed.
- 3. Typed a password or other login details. Change that password, and change it anywhere else it was reused, since a reused password leaves other accounts open to the same attacker. Confirm multi-factor authentication is turned on, and sign the account out of all sessions or revoke its active sessions rather than assuming the password change alone ends it, since a real-time phishing page can act on a captured login within seconds. Have IT review the account for anything set up during that window, such as a new MFA method, a connected app, or a forwarding rule. If what was typed was banking or payment information, contact the financial institution directly through a verified number or its official site immediately, since that account is outside what your IT provider can freeze or reverse.
- 4. Downloaded and ran a file. Disconnect the device from the network first, before changing anything, since malware already running on that device can capture a new password or session just as easily as the old one. From a different, known-clean device, then change passwords and revoke sessions as in step 3 above. Have IT check the disconnected device itself for information-stealing malware and any signs of continued access before it is reconnected or the account is treated as clean.
Cyber One Solutions helps businesses close the gaps malvertising relies on, including phishing-resistant multi-factor authentication on the accounts that matter and staff who have seen these scams before they land. If you are not sure whether a scam ad like this would catch your team off guard today, contact us and we will take a look.
Frequently Asked Questions
Aren't ads at the top of Google checked and safe?
Google reviews ads and removes billions that break its rules, but attackers have been documented showing reviewers a clean page while routing everyone else to the malicious one. A "Sponsored" label is not proof the destination is safe.
What is malvertising?
Malvertising is short for malicious advertising. Scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.
How do I download software safely?
Go to the maker's official website by typing the address yourself, or use a bookmark you already trust. If you search instead, confirm the result is the vendor's own domain before downloading; SEO tricks can push a lookalike site into the normal, non-ad results too, so being non-sponsored is not by itself proof a result is official.
Does an ad blocker help?
It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It is not a complete fix on its own, so keep the habits above in place too.
