Google, X ads found promoting sites containing crypto drainer malware

Ads on Google and X were found promoting sites containing a cryptocurrency drainer that stole $59 million from thousands of users

December 23, 2023 04:47 pm | Updated 04:47 pm IST

Advisements on Google and X, formerly Twitter, were found promoting sites containing a cryptocurrency drainer.

Advisements on Google and X, formerly Twitter, were found promoting sites containing a cryptocurrency drainer. | Photo Credit: Reuters

Advisements on Google and X, formerly Twitter, were found promoting sites containing a cryptocurrency drainer that had reportedly stolen $59 million from 63,210 victims over the past nine months.

Thousands of phishing sites were discovered that were using the drainer between March 2023 to today with spikes in activity noticed in May, June and November, a report from Bleeping Computer said.

The sites with drainers were being promoted in Google Search via malicious ads. Many of the ads were found to be exploiting a loophole in Google’s tracking template to make their URLs appear to belong to official domains.

On X, advertisements were found to be way more prevalent. These ads were found to be posted from legitimate “verified” accounts that carried the blue tick badge when the ad was shown.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

The ads on X were also promoting NFT airdrops and new token launches on sites that contain the drainer.

A drainer is a malicious smart contract, or a suite designed to drain funds from a user’s cryptocurrency wallet without their consent.

The drainer works by taking users to a legitimate looking website that tricks them into approving malicious contracts, allowing the drainer to perform unauthorised transactions from the victim’s crypto wallet address.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.