Wednesday, April 30, 2008

Phishing Google AdWords


Customers of Google AdWords, and even some that are not, have been the target of a phishing scam that has continued throughout April with fervor. Normally this had been a tactic that used to be reserved for your banking site, but as of late the authors of these phishing scams have really begun to find other indirect routes in order to drain your savings.
The scam emails arrived in inboxes with subject lines such as: “Please re-submit your payment information.”
“Account Reactivation”
“Please Update Your Billing Information”
“Your Account with Google AdWords”
“Your AdWords Google Account is stoped.”
“Your ads in this account are not running”
The emails themselves are all very similar and don’t have the misspellings that the subject lines have. They claim that your Google ads will cease to run unless your billing information is updated soon. A link in the emails appear to direct you to http://adwords.google.com/select/login, however if you hover your mouse pointer over the link, you’ll notice that they actually send you to various domains hosted on a fast flux network in China that look more like this: http://www.adwords.google.com.serga01.cn/select/Login, adding the “adwords.google.com.” as a sub domain in order to make the actual destination appear to be Google.
AppRiver continues to block all of these attacks

0 comments: