Skip to content

Security1 publisher2 min readPublished

Ledger phishing ads ran under a verified Google advertiser and routed victims through Google Sites

Zscaler found Ledger phishing ads running under a verified Google advertiser, with Vercel redirect domains rotating every 15 to 20 minutes. The ad displayed google.com and the pages sat on Google and Vercel hosting, so domain reputation and the verified badge gave defenders little to catch.

The Watch · Security desk

Illustration accompanying Ledger phishing ads ran under a verified Google advertiser and routed victims through Google Sites

What happened

  • In August 2026, Zscaler ThreatLabz found sponsored Google ads on Ledger-related searches, served from a Google-verified advertiser account and aimed at users in the US, Europe and parts of Asia.
  • The Vercel domain in the JavaScript redirect changed roughly every 15 to 20 minutes while Zscaler observed the campaign.
  • The fake page asked victims for their secret recovery phrase and sent what they typed to an attacker-controlled Vercel domain.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure If Zscaler's compromise theory holds, an old verified advertiser account with a clean record is worth stealing, because its badge and history carry over to whoever buys ads with it next.
  • constraint Domain blocklists built from captured samples fall behind a chain that swaps its redirect three to four times an hour, and the Google-hosted hops at either end are poor blocking targets.
  • constraint If the visitor telemetry works as Zscaler suggests, automated sandbox detonation of the link is the check the page was built to recognise and dodge.
  • exposure A Ledger owner who types the phrase into this page gives the attacker the wallet, and the attacker needs no device to use it.

Every signal a searcher or a filter would check pointed at a trusted name. The ad's display line showed google.com beside "10L+ visits in the past month" [6]. "10L" means one million in Indian numbering, and Zscaler says the count appears to describe google.com, not the phishing destination [6]. The advertiser panel listed a verified identity located in Germany [4].

ThreatLabz describes the advertiser as a long-standing, verified account with no observed history of malicious ads [3]. It says the operator may have compromised that account to run the campaign [3]. If it happened, the badge vouched for the account's history and its registered owner, and the campaign ran on that record. Zscaler attributes the campaign only to unnamed threat actors, and its analysis does not put a number on victims or stolen funds [15].

Both ends of the redirect chain were Google services: Cloud Storage for the first hop and Sites for the page the victim saw [7]. The Ledger content inside the Sites iframe came from Vercel-hosted domains [7]. At the rotation Zscaler observed, the operator went through three to four Vercel redirect domains an hour [1]. ThreatLabz says that rotation made the activity harder to detect by domain reputation [8]. An indicator taken from one captured sample pointed at a redirect the chain had moved off within about 20 minutes [8].

The page also profiled its visitors. It collected device metadata, logged keypresses, touches and mouse movements, and sent the data to a Vercel endpoint [10]. Zscaler says that could let the operators separate real visitors from automated analysis tools [10]. A Cloudflare Web Analytics beacon, beacon.min.js, ran on the page with an analytics token configured [11].

The lure copied Ledger's interface and offered app downloads for Windows, macOS, Linux and mobile [9]. Choosing a device brought up "Connecting your Ledger" and "Initializing Firmware Update," then a claim that the device was connected and a request to confirm ownership [12]. The recovery-phrase form came next, with autocomplete on the entry field [12]. Every device message on the page was part of a fake verification process [12]. Zscaler says a phrase captured this way lets attackers reach the wallet without the physical hardware [14].

What to watch

  • Whether Google confirms the verified advertiser account was taken over, or says how the ads passed its review.
  • Publication of the rotating Vercel domains or the Cloudflare analytics token as indicators, which would let defenders hunt across the rotation.
  • Reports of drained Ledger wallets traced to this redirect chain, which would put a victim count and a loss figure on the campaign.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories