New Wave of Malicious Google Ads Deploys Advanced Screen-Freezing Tech Support Scams Across Windows and Mac Platforms

Cybersecurity researchers have uncovered a sophisticated and widespread campaign abusing Google Ads to distribute advanced tech support scams capable of freezing both Windows and macOS devices. The malicious advertisements, which surfaced aggressively across the web during a two-week monitoring window, utilized aggressive browser-locking techniques to simulate catastrophic system failures. By tricking users into believing their hardware had crashed or been compromised by malware, the fraudulent ads coerced unsuspecting visitors into calling bogus support hotlines operated by cybercriminals.
The campaign highlights a troubling evolution in cyber threat actor methodologies. Rather than relying solely on traditional phishing emails or malicious email attachments—methods that have been heavily mitigated by modern spam filters and enterprise email security solutions—fraudsters are increasingly weaponizing legitimate digital advertising infrastructure. By purchasing ad space through standard programmatic advertising networks, these bad actors managed to bypass initial publisher vetting processes, injecting their malicious payloads directly into high-traffic mainstream websites.
Anatomy of the Attack and Psychological Manipulation
According to technical analysis published by cloud security firm Netskope, the operation relied on an elaborate blend of client-side scripting designed to hijack browser sessions. When an unsuspecting user clicked on what appeared to be a standard, legitimate advertisement, the underlying code triggered a full-screen display locker.
This locker was engineered to execute several disruptive behaviors simultaneously: it completely filled the viewport, hid the user’s cursor, intercepted and swallowed standard exit keystrokes such as Alt-F4 or Cmd-Q, and severely taxed the browser’s resource allocation to generate noticeable lag. To the average computer user, the symptoms were indistinguishable from a severe operating system crash or a ransomware infection.
The visual interface presented during the freeze typically mimicked blue-screen-of-death errors on Windows or critical warning dialogues on macOS. Bold, urgent typography instructed the panicked user to immediately dial a toll-free telephone number to speak with certified technical support personnel who could supposedly rescue their data and restore system functionality.
Security researchers emphasize that despite the convincing illusion of a system-wide seizure, the underlying hardware and operating system remained entirely unharmed and uncompromised. Nothing on the computer was actually locked, encrypted, or damaged. The entire encounter was a psychological performance engineered to manufacture acute panic, time pressure, and disorientation.
Once victims placed the phone call, the human element of the scam commenced. The fraudulent call center operators deployed high-pressure social engineering tactics, urging callers to pay exorbitant fees for unnecessary software licenses, hand over remote desktop access to their machines under the guise of diagnostic troubleshooting, or divulge sensitive personal and financial data, including credit card numbers and online banking credentials.
Timeline and Scope of the Campaign
The sophisticated ad-fraud and tech-support campaign was meticulously documented by Netskope threat hunters over a specific observation window spanning from August 31 to September 14. During this active period, telemetry data revealed that users from 619 distinct enterprise customer organizations successfully clicked on the malicious advertisements.
Fortunately, because these organizations utilized Netskope’s security platforms, the payloads were intercepted and blocked before the victims could interact with the call centers. Consequently, direct financial losses among the monitored corporate cohorts were mitigated to zero. However, security analysts stress that these figures represent merely a microscopic fraction of global internet traffic. The true breadth of the campaign—encompassing everyday consumers, unmonitored small businesses, and individuals browsing from home networks—is believed to be exponentially higher.
During their investigation, Netskope analysts tracked more than 250 distinct Google Ads campaign IDs actively distributing the fake security lockers. These malicious ads were successfully served across at least 284 legitimate publisher websites. Far from being relegated to obscure corners of the dark web, the ads appeared prominently on high-traffic mainstream portals, including popular mapping services, real-estate listings, weather forecasting platforms, document-hosting utilities, and major sports commentary networks.
Geographic Distribution and Demographic Vulnerability
An analysis of the organizational telemetry collected during the two-week observation window provides a clear picture of the campaign’s geographic distribution. Approximately 62 percent of the targeted organizations were based within the United States, making the U.S. the primary geographic focus for the threat actors. Japan and Australia ranked second and third, respectively, accounting for significant portions of the remaining recorded interactions.
This global spread underscores the borderless nature of modern digital advertising abuse. Cybercrime syndicates routinely leverage programmatic bidding systems to target affluent English-speaking and developed digital economies where consumer purchasing power is high and reliance on digital devices is ubiquitous.
Security experts and industry commentators have frequently noted a cultural tendency among tech-savvy internet users to dismiss victims of such scams, often resorting to victim-blaming or ridicule. However, cybersecurity analysts argue that such a cynical perspective fundamentally misunderstands the demographics of the modern internet.
A substantial and critical portion of the global population possesses little to no formal understanding of computer architecture, networking protocols, or browser mechanics. These users navigate the digital world out of functional necessity—to file taxes, communicate with relatives, pay utility bills, or manage banking—while simultaneously facing an increasingly cluttered, confusing, and hostile web environment dominated by aggressive pop-ups, misleading navigation prompts, and deceptive advertising formats.
Combined with the natural human inclination to seek quick resolutions to unexpected interruptions, this fundamental lack of technical literacy turns everyday internet users into prime targets. Security professionals note that even highly educated individuals can be temporarily disoriented when confronted with a sudden, seemingly catastrophic technical failure on a critical work device. Furthermore, industry observers point out that many of the harshest online critics undoubtedly have close friends, elderly relatives, or colleagues who fall squarely into this vulnerable demographic.
Broader Industry Implications and the Challenge of Malicious Advertising
The exploitation of programmatic advertising platforms—often referred to in the cybersecurity industry as malvertising—represents a persistent and systemic challenge for technology giants, ad networks, and enterprise defenders alike.
Programmatic advertising operates on a massive, highly automated scale. Billions of ad impressions are bought, sold, and rendered across the global web every single second through complex networks involving advertisers, ad exchanges, demand-side platforms (DSPs), and supply-side platforms (SSPs). Threat actors routinely exploit this intricate ecosystem by establishing shell companies, using stolen or synthetic identities to pass vetting checks, and deploying cloaking techniques that present benign content to automated ad-review crawlers while serving malicious payloads exclusively to human end-users.
Google and other major digital advertising platforms maintain strict policies against deceptive financial practices, malware distribution, and technical support scams. Tech companies invest heavily in automated machine learning classifiers, cryptographic verification protocols, and human review teams to identify and purge fraudulent campaigns from their ad networks. Every year, search and social platforms take down tens of millions of violating ads and suspend hundreds of thousands of advertiser accounts.
Despite these ongoing mitigation efforts, sophisticated adversaries continuously adapt their tactics. By rotating domain names, obfuscating JavaScript code, utilizing decentralized hosting infrastructure, and rapidly swapping campaign IDs, cybercrime rings manage to keep their malicious advertisements active for days or even weeks before detection algorithms can isolate and neutralize them.
The Response from Security Vendors and Recommendations for Users
The disclosure by Netskope underscores the vital role that advanced endpoint protection, secure web gateways, and cloud-access security brokers (CASBs) play in modern enterprise security architectures. By inspecting network traffic in real-time, blocking malicious domains at the DNS level, and neutralizing client-side browser lockers before they can fully render, security solutions protect users even when human judgment falters under pressure.
To combat the rising tide of malvertising and tech support scams, cybersecurity authorities and consumer advocacy groups recommend a comprehensive set of defensive hygiene practices for both individual users and organizational administrators:
First, users are advised to deploy reputable, modern ad-blocking software and browser extensions. By stripping out programmatic advertisements entirely from web pages, ad blockers remove the primary vector through which malvertising campaigns reach the browser.
Second, individuals should familiarize themselves with the definitive signs of browser-based technical support scams. Legitimate technology companies such as Microsoft, Apple, Google, or major antivirus vendors will never display full-screen pop-up windows featuring flashing warning codes, audio alarms, or direct telephone numbers urging immediate calls for system repair.
Third, if a browser appears to freeze or become unresponsive due to a suspected malicious web page, users should avoid panicking or calling the displayed phone number. Instead, the standard protocol involves force-closing the browser application. On Windows devices, this can be achieved by opening the Task Manager using the Ctrl-Shift-Esc shortcut, selecting the frozen browser process, and clicking End Task. On macOS, users can press Option-Command-Escape to open the Force Quit Applications menu, select the affected browser, and click Force Quit.
Finally, organizations are urged to continuously conduct security awareness training for employees, emphasizing that cybercriminals increasingly weaponize legitimate-looking web infrastructure to execute social engineering attacks. By fostering a security-conscious culture that encourages employees to report suspicious browser behavior without fear of reprisal, organizations can significantly reduce their overall exposure to programmatic fraud.
As the digital economy continues to expand and bad actors refine their automated exploitation techniques, the security community remains vigilant. Campaigns like the one uncovered by Netskope serve as a stark reminder that the battle against cybercrime extends far beyond traditional malware detection, requiring a coordinated, multi-layered approach encompassing platform governance, technological enforcement, and continuous public education.







