Cybercriminals target users who click on the first link in search engine results by promoting fake sites through Google Ads.
Google blocked 415 million ads in 2024 for rule violations, including scams, highlighting the scale of the issue.
Scammers create fake Semrush pages to phish for SEO professionals' credentials, using similar domain names and Google Ads for promotion.
Fake pages imitate legitimate sign-in processes to steal Semrush or Google account credentials.
Another tactic involves promoting fake Google Ads within Google Ads by leveraging Google Sites to create convincing phishing pages.
Google acted swiftly to remove these malicious sites from search results, but comprehensive solutions require proactive steps.
To protect against phishing attacks, organizations should encourage bookmarking trusted sites, conduct security awareness training, and implement multi-factor authentication.
It is recommended to deploy robust security solutions on all company devices to prevent visits to malicious websites.