A cloud-hosted tech-support scam is using Google Ads to lead users to fake security warnings that appear to take over their browsers.
Threat Labs says the attackers want victims to call a bogus support number, where they may be pressured to pay for fake help, grant remote access, or share personal and financial information.
The researchers did not report that the page itself installs malware; the danger is what a victim may be persuaded to do after calling.
After an ad click, the victim sees a page with a loading spinner and two buttons, “Cancel” and “Continue.” It then appears to become an ordinary online store called ShopEase.
Behind that harmless-looking page, the scam kit waits for a mouse movement before running its hidden code. Netskope says this step helps it avoid automated scanners that inspect pages without moving a cursor.
Fake Security Locker Hijacks Browsers
Once the cursor moves, the page uses a hardcoded AES key to decrypt the address of its command-and-control server. It fetches an encrypted locker payload suited to the visitor’s operating system and decrypts it with a second key.
The fake warning is assembled in browser memory rather than delivered as a separate, easily inspected page. If the server cannot be reached or decryption fails, the storefront remains on screen.
Windows visitors see a fake Microsoft Defender Security Center scan claiming their computer is infected. Mac visitors see a similar warning styled around an Apple storefront.
Both versions repeatedly display a phone number and try to make the problem feel urgent. The first click on the locker switches the browser to full-screen mode, hiding its tabs and address bar.
The page also hides the cursor, tries to block exit keys through the browser’s keyboard-lock API, plays alert sounds, and deliberately makes the browser lag.
A black warning screen flashes over the page, while an attempt to close the tab can trigger a confirmation dialog carrying the scam message. The computer itself is not locked: the effects are confined to the browser.
Netskope linked most visits to paid Google ads using click-tracking parameters, including gclid, gad_source, and gad_campaignid.
From August 31 through September 14, 2026, it observed the kit reaching at least 619 organizations across 457 scam hosts.
Researchers counted more than 250 Google Ads campaign IDs associated with ads on at least 284 legitimate publisher sites. The publishers were not reported as compromised.
If the warning appears, do not call the number or grant remote access. Netskope advises holding Escape for a couple of seconds to leave full-screen mode, then closing the tab.
If that fails, force-close the browser using the operating system and reopen it without restoring the previous session. Netskope detects the kit as Generic.Phishing Tech Support Scam Kit Detected.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team