Cybercriminals Exploit Google Ads in Phishing Scheme Targeting ManageWP Users
Hackers hijack Google Ads to spread phishing campaign spoofing top GoDaddy tool
Techradar Sg
Image: Techradar Sg
Cybercriminals are using Google Ads to deceive users of ManageWP, a GoDaddy service for managing WordPress sites, into entering their login credentials on fake pages. Over 200 victims have been confirmed, with attackers capturing sensitive information including two-factor authentication codes.
- 01Cybercriminals are targeting ManageWP users through malicious Google Ads.
- 02The phishing scheme captures login credentials and 2FA codes.
- 03At least 200 victims have been reported so far.
- 04The phishing framework appears to be custom-built and not part of a commercial kit.
- 05The platform includes a Russian-language user agreement disclaiming responsibility for illegal use.
Advertisement
In-Article Ad
Cybercriminals are hijacking Google Ads to target users of ManageWP, a cloud-based service by GoDaddy that allows management of multiple WordPress sites. Security researchers from Guardio Labs discovered that attackers are using sponsored search results to direct users to fake login pages designed to capture not only their login credentials but also two-factor authentication (2FA) codes. The phishing scheme has already affected at least 200 victims, who have been alerted about the attack. The malicious ads appear at the top of search results when users look for ManageWP or similar services. The fake landing page closely resembles the legitimate site, making it difficult for users to identify the scam. Guardio Labs accessed the attackers' command-and-control infrastructure, revealing a custom Russian-language phishing framework that is not part of a commercial kit. This framework includes a user agreement that denies responsibility for illegal activities and states that it is intended for educational purposes only. The platform also prohibits targeting Russians or leaking generated data publicly.
Advertisement
In-Article Ad
Users of ManageWP are at risk of credential theft, which could lead to unauthorized access to their websites and sensitive data.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about phishing attacks targeting online services?
Connecting to poll...
Read the original article
Visit the source for the complete story.


