Scareware Ads Persist on Google’s Transparency Tool Despite Reports

www.news4hackers.com-scareware-ads-persist-on-google-s-transparency-tool-despite-reports-scareware-ads-persist-on-google-s-transparency-tool-despite-reports

Scareware advertisements continue to operate within Google’s ad transparency framework despite being flagged by researchers, according to a study conducted by a team from New York University and Radboud University.

Study Findings

The investigation, which analyzed Google’s Ads Transparency Center—a public repository established to comply with regulations such as the EU’s Digital Services Act—revealed that reporting deceptive ads does not guarantee their removal. The research team developed a tool named AdLens to identify malicious advertisements, uncovering significant gaps in Google’s enforcement mechanisms.

AdLens Tool

The AdLens system processed 188,000 software-related ad creatives from the archive using a two-tiered approach. First, it employed a similarity search to identify potential threats, followed by open-source language models to validate findings.

Results of Analysis

This process uncovered 238 scareware ads, 3,346 deceptive advertisements, and 258 instances where ad creators obscured their identities. Collectively, these ads generated over 100 million impressions in Europe alone.

Scareware Campaigns

Scareware campaigns often featured alarming claims, such as warnings about severe phone damage from multiple viruses or false notifications about storage capacity.

Deceptive Ads

Deceptive ads included promises of recovering deleted photos or tracking phone locations via phone numbers. One ad in this category remained active for over two years, accumulating 14.5 million impressions.

Minimal Content Ads

A separate category of ads used minimal content, such as buttons labeled “Continue” or QR codes with no clear purpose. A French ad of this type generated 1.6 million impressions without disclosing its origin or function.

Testing Google’s Reporting System

The researchers tested Google’s reporting system by submitting a sample of flagged ads through the standard “Report this ad” feature. Results were inconsistent: some ads were removed, while others remained visible despite being classified as violations. In one instance, Google acknowledged a publicly visible scareware ad as a breach but allowed it to continue running.

Misleading Domains

The study also linked some landing pages to malicious domains flagged by threat intelligence services, including one associated with the TamperedChef malware campaign. While a single ad linked to this domain was taken down, 41 others pointing to the same domain remained active.

Collaboration and Challenges

Ritik Roongta, a NYU researcher involved in the project, stated the team has sought collaboration with Google’s trust and safety division to improve reporting processes. A domain-based blocking system, rather than individual ad removal, could address the recurring issue of malicious content reappearing. However, the dynamic nature of these domains—frequently changing registrars and hosting providers—poses challenges for maintaining effective blocklists.

Ritik Roongta, a NYU researcher involved in the project, stated the team has sought collaboration with Google’s trust and safety division to improve reporting processes.

AdLens Tool’s Potential

The AdLens tool’s low operational cost, estimated at under $100 for processing 188,000 ads, highlights its potential for use by smaller organizations, regulators, or watchdogs. The system, built on open-source models, could be adapted to other platforms like Meta or Amazon, as well as other sectors such as healthcare or gambling. The researchers emphasized the tool’s modularity, noting it currently supports text and image-based ads with plans to incorporate video in future updates.

Google’s Ad Library and Transparency

Google’s ad library, as revealed by the study, contains a broader volume of problematic content than previously understood. However, the lack of a response from Google’s security team leaves unresolved questions about the platform’s ability to address these vulnerabilities. The findings underscore the need for systemic improvements in ad moderation and transparency, particularly as malicious actors increasingly exploit digital advertising ecosystems.



About Author

en_USEnglish