Table of Contents
Background
Malicious Advertisements
Object of attack
Malicious Sites
Malicious Advertisers
ROI Estimation
Conclusion
Home web3.0 The easiest scam to fall for: Detailed explanation of Google and Baidu's cryptocurrency fake advertising principles

The easiest scam to fall for: Detailed explanation of Google and Baidu's cryptocurrency fake advertising principles

Feb 22, 2024 pm 02:20 PM
Blockchain advertise cryptocurrency trick

php editor Youzi will analyze the easiest scam for you: a detailed explanation of the principle of Google Baidu cryptocurrency fake advertising. In recent years, the cryptocurrency market has been turbulent and attracted the attention of a large number of investors. However, some criminals use search engines such as Google and Baidu to place false advertisements and induce users to click on links to engage in fraudulent activities. This article will delve into the principles behind these scams, help readers identify traps, and improve network security awareness.

Original Text | ScamSniffer

Compilation | Wu Shuo Blockchain

Background

In recent weeks, ScamSniffer conducted a survey and found that many users were using Google Falling victim to a phishing scam while searching for ads. These users inadvertently clicked on malicious ads and were induced to visit fraudulent websites, resulting in serious financial losses.

Malicious Advertisements

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

The investigation found that a large number of malicious advertisements appeared at the top of the keyword search results used by the victims. Most users are unaware of how deceptive search ads can be and therefore often click on the first available option, which can lead them to fake and malicious websites.

Object of attack

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

Keyword analysis shows that some malicious ads and websites target projects such as Zapper, Lido, Stargate, Defillama, Orbiter Finance and Radiant. . Malvertising related to each keyword is summarized below.

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

Malicious Sites

When you encounter a malicious ad in Zapper, you may notice that it attempts to use a Permit signature to gain access to my $SUDO Authorization. If you use the Scam Sniffer plugin, you will receive timely alerts about potential risks.

Currently, many wallets do not have clear risk warnings for this kind of signature, and ordinary users may think it is a normal login signature and sign it without thinking.

Malicious Advertisers

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

Analysis of malicious ad messages identified the following advertisers as responsible for serving these ads:

##●● ТОВАРИСТВО З ОБМЕЖЕНОЮ ВІДПОВІДАЛЬНІСТЮ «РОМУС-ПОЛІГРАФ (from Ukraine)

● TRACY ANN MCLEISH (from Canada)

Bypass review

Malicious ads use a variety of techniques to bypass Google's ad review Process, including:

Parameter differentiation

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

Fraudulent websites use gclid Google Ads parameters for tracking clicks, displaying different pages based on the user's source. This allows them to display normal web pages during the review phase, effectively bypassing Google's ad review process.

Debugging Prevention

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

Some malicious ads use anti-debugging measures to redirect users to normal websites when developer tools are enabled, and when accessed directly Redirect to malicious website. This tactic helps bypass some of the scrutiny from the Google ad machine.

These bypass techniques allow malicious ads to deceive Google's ad review process, ultimately causing significant losses to users.

Improvement Suggestions for Google Ads

● Integrate a Web3-centered malicious website detection engine

● Continuously monitor the landing page throughout the entire advertising life cycle, and use parameters in a timely manner Identifying dynamic switching or spoofing

Stolen estimates

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

On-chain data analysis of addresses associated with malvertising sites in the ScamSniffer database shows that approx. Approximately $4.16 million was stolen from 3,000 victims, with the majority of the thefts occurring in the last month.

Details:

https://dune.com/scamsniffer/google-search-ads-phishing-stats

Fund flow

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

By analyzing several larger fund collection addresses, we found that some funds were deposited in SimpleSwap, Tornado.Cash, KuCoin, Binance, etc.

0xe018b11f700857096b3b89ea34a0ef5133963370

0xdfe7c89ffb35803a61dbbf4932978812b8ba843d

0x4e1daa2805b3b4f4d155027d754 9dc731134669a

0xe567e10d266bb0110b88b2e01ab06b60f7a143f3

0xae39cd591de9f3d73d2c5be67e72001711451341

ROI Estimation

The easiest scam to fall for: Detailed explanation of Google and Baidus cryptocurrency fake advertising principles

# Advertising analytics platforms indicate that the average cost per click for these keywords is approximately $1-2. Based on a projected conversion rate of 40% and 7,500 users clicking on the ad, the advertising cost would be approximately $15,000. Based on cost-per-click, the expected ROI is approximately 276%.

Conclusion

The analysis shows that the advertising cost of most phishing ads is relatively low. Through technical means and disguise, these malicious ads successfully deceived Google's ad review process, causing them to be seen by users and cause significant harm.

To minimize the risk of falling victim to this type of scam, users should remain vigilant when using search engines and actively block content in advertising areas. Additionally, Google Ads’ enhanced review process for Web3 malvertising is critical to better protect users.

Finally, thanks to 23pds@SlowMist, @Tay, bax1337@ConvexLabs, SunSec@DeFiHackLabs, ZachXBT, and Teddy@Biteye for reviewing the data and content!

The above is the detailed content of The easiest scam to fall for: Detailed explanation of Google and Baidu's cryptocurrency fake advertising principles. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. Best Graphic Settings
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. How to Fix Audio if You Can't Hear Anyone
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
WWE 2K25: How To Unlock Everything In MyRise
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

okx Ouyi Exchange web version enter link click to enter okx Ouyi Exchange web version enter link click to enter Mar 31, 2025 pm 06:21 PM

1. Enter the web version of okx Euyi Exchange ☜☜☜☜☜☜ Click to save 2. Click the link of okx Euyi Exchange app ☜☜☜☜ Click to save 3. After entering the official website, the clear interface provides a login and registration portal. Users can choose to log in to an existing account or register a new account according to their own situation. Whether it is viewing real-time market conditions, conducting transactions, or managing assets, the OKX web version provides a simple and smooth operating experience, suitable for beginners and veterans. Visit OKX official website now for easy experience

gate.io registration tutorial gate.io registration tutorial Mar 31, 2025 pm 11:09 PM

This article provides a detailed Gate.io registration tutorial, covering every step from accessing the official website to completing registration, including filling in registration information, verifying, reading user agreements, etc. The article also emphasizes security measures after successful registration, such as setting up secondary verification and completing real-name authentication, and gives tips from beginners to help users safely start their digital asset trading journey.

What is Ouyi for? What is Ouyi What is Ouyi for? What is Ouyi Apr 01, 2025 pm 03:18 PM

OKX is a global digital asset trading platform. Its main functions include: 1. Buying and selling digital assets (spot trading), 2. Trading between digital assets, 3. Providing market conditions and data, 4. Providing diversified trading products (such as derivatives), 5. Providing asset value-added services, 6. Convenient asset management.

How to roll positions in digital currency? What are the digital currency rolling platforms? How to roll positions in digital currency? What are the digital currency rolling platforms? Mar 31, 2025 pm 07:36 PM

Digital currency rolling positions is an investment strategy that uses lending to amplify trading leverage to increase returns. This article explains the digital currency rolling process in detail, including key steps such as selecting trading platforms that support rolling (such as Binance, OKEx, gate.io, Huobi, Bybit, etc.), opening a leverage account, setting a leverage multiple, borrowing funds for trading, and real-time monitoring of the market and adjusting positions or adding margin to avoid liquidation. However, rolling position trading is extremely risky, and investors need to operate with caution and formulate complete risk management strategies. To learn more about digital currency rolling tips, please continue reading.

ok official portal web version ok exchange official web version login portal ok official portal web version ok exchange official web version login portal Mar 31, 2025 pm 06:24 PM

This article details how to use the official web version of OK exchange to log in. Users only need to search for "OK ​​Exchange Official Web Version" in their browser, click the login button in the upper right corner after entering the official website, and enter the user name and password to log in. Registered users can easily manage assets, conduct transactions, deposit and withdraw funds, etc. The official website interface is simple and easy to use, and provides complete customer service support to ensure that users have a smooth digital asset trading experience. What are you waiting for? Visit the official website of OK Exchange now to start your digital asset journey!

How to calculate the transaction fee of gate.io trading platform? How to calculate the transaction fee of gate.io trading platform? Mar 31, 2025 pm 09:15 PM

The handling fees of the Gate.io trading platform vary according to factors such as transaction type, transaction pair, and user VIP level. The default fee rate for spot trading is 0.15% (VIP0 level, Maker and Taker), but the VIP level will be adjusted based on the user's 30-day trading volume and GT position. The higher the level, the lower the fee rate will be. It supports GT platform coin deduction, and you can enjoy a minimum discount of 55% off. The default rate for contract transactions is Maker 0.02%, Taker 0.05% (VIP0 level), which is also affected by VIP level, and different contract types and leverages

What are the recommended websites for virtual currency app software? What are the recommended websites for virtual currency app software? Mar 31, 2025 pm 09:06 PM

This article recommends ten well-known virtual currency-related APP recommendation websites, including Binance Academy, OKX Learn, CoinGecko, CryptoSlate, CoinDesk, Investopedia, CoinMarketCap, Huobi University, Coinbase Learn and CryptoCompare. These websites not only provide information such as virtual currency market data, price trend analysis, etc., but also provide rich learning resources, including basic blockchain knowledge, trading strategies, and tutorials and reviews of various trading platform APPs, helping users better understand and make use of them

Official website entrance of major digital currency trading platforms 2025 Official website entrance of major digital currency trading platforms 2025 Mar 31, 2025 pm 05:33 PM

This article recommends ten mainstream cryptocurrency exchanges, including Binance, OKX, Sesame Door (gate.io), Coinbase, Kraken, Bitstamp, Gemini, Bittrex, KuCoin and Bitfinex. These exchanges have their own advantages, such as Binance is known for its largest trading volume and rich currency selection in the world; OKX provides innovative tools such as grid trading and a variety of derivatives; Coinbase focuses on US compliance; Kraken attracts users for its high security and pledge returns; other exchanges have their own characteristics in different aspects such as fiat currency trading, altcoin trading, high-frequency trading tools, etc. Choose an exchange that suits you, and you need to use your own investment experience