AI-Generated Articles Used In Google Discover Abuse Campaign To Push Malware Alerts

Researchers from HUMAN’s Satori Threat Intelligence and Research Team have uncovered a sophisticated ad fraud and social engineering campaign leveraging AI-generated news stories to manipulate Google Discover feeds and push malicious notifications to users.

The operation, dubbed Pushpaganda,” combines automated content creation, SEO abuse, and push notification exploitation to distribute scareware, fake alerts, and fraudulent advertisements at scale.

At its peak, HUMAN observed more than 240 million ad bid requests linked to Pushpaganda-controlled domains within a single week.

The operation initially focused on Android and Chrome users in India but has since expanded to include the United States and Australia.

Following the disclosure, Google confirmed that a fix had been implemented to prevent deceptive or low-quality AI-generated content like that used in Pushpaganda from surfacing in Discover feeds.

Exploiting Google Discover Feeds For Scareware Delivery

Pushpaganda’s attack model combines search engine optimization (SEO) manipulation with push-based social engineering.

Threat actors created a network of 113 domains, each hosting AI-generated news articles with sensational or fear-inducing headlines designed to attract clicks.

These fake stories inserted into personalized Google Discovery feeds often appeared alongside legitimate news, increasing their credibility and click rate.

Google Discover Push Scam (Source: humansecurity)
Google Discover Push Scam (Source: humansecurity)

The campaign maximized exposure through high-rotation content and AI-crafted engagement lures. Thematically, most of the articles fit into a handful of categories:

  • Financial or political hooks, such as tax updates or “instant government deposit” notifications.
  • Tech hyperbole, including clickbait claims about ultra-cheap smartphones or exaggerated hardware specs.
  • Celebrity or medical endorsements are often paired with deepfaked images or videos inserted into advertising slots.

Satori analysts further confirmed that Pushpaganda sites used JavaScript-based rotation mechanisms that automatically cycled inactive browser tabs through actor-owned pages.

This inflated user engagement metrics and created false advertising value, simulating authentic browsing behavior.

Diagram outlining the Pushpaganda threat (Source: humansecurity)
Diagram outlining the Pushpaganda threat (Source: humansecurity)

A notable aspect of Pushpaganda is its integration of AI-generated images and deepfakes into paid ad placements.

Many showcased manipulated visuals of celebrities or medical professionals endorsing financial or health-related schemes.

These fabricated identities increased user trust, drawing victims deeper into scam loops and further obfuscating the malicious intent behind the campaigns.

Google Discover Push Scam (Source: humansecurity)
Google Discover Push Scam (Source: humansecurity)

HUMAN’s research emphasizes disrupting the monetization cycle at its source. Through its Ad Fraud Defense and Ad Click Defense platforms, the company automatically identifies and filters invalid bid requests associated with Pushpaganda-related domains.

This proactive filtering helps advertisers and publishers avoid financial losses linked to fraudulent ad impressions.

Google has deployed measures to prevent the inclusion of low-quality, manipulative, or AI-generated scareware content in personalized Discover feeds.

Nonetheless, Satori researchers continue to monitor the infrastructure and track potential evolution of Pushpaganda tactics anticipating further actor adaptation or rebranding.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories