Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Hackers weaponize Google Ads: Graphic designers falling for fake tools

The malvertising campaigns have been continuous since November 13, 2024, and leverage numerous domains to distribute harmful content

byKerem Gülen
December 17, 2024
in News

Silen Push researchers have identified a series of malvertising campaigns targeting graphic design professionals, taking advantage of Google Search ads to distribute malware. The attacks began in November 2024 and utilized two IP addresses, 185.11.61.243 and 185.147.124.110, to host multiple malicious domains. These ads redirect users to websites that initiate harmful downloads, posing a significant security threat to unsuspecting victims.

Hackers exploit Google ads to target graphic designers

The primary attack vector involves fraudulent domains that mimic legitimate graphic design software, with campaigns launching nearly daily. Notable domains connected to this scheme include frecadsolutions.com, freecad-solutions.net, and rhino3dsolutions.io. Each campaign has reportedly made use of dedicated IP addresses to mask the malicious activity behind seemingly legitimate advertising.

The malvertising campaigns have been continuous since November 13, 2024, and leverage numerous domains to distribute harmful content. The first campaign was hosted on frecadsolutions.com and became active on November 6, 2024. Subsequent campaigns utilized slightly altered domain names to evade detection, with campaigns noted on sites like planner5design.net and variations of freecad-solutions.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

As detailed in the findings from Silent Push, the malicious actors have orchestrated a well-structured operation. By exploiting vulnerabilities in ad networks, these attackers redirect users from Google ads to malicious websites that offer deceptive software downloads masquerading as CAD tools. The use of tools hosted on trusted platforms such as Bitbucket adds credibility to their malicious links, increasing the likelihood of downloads by unsuspecting users.

Moreover, Silent Push emphasizes that identifying these threats should be simple through basic domain and IP address investigations, yet the attackers continue to operate undeterred, highlighting potential flaws in Google’s ad monitoring capabilities. Research indicates that up to ten distinct campaigns have utilized the same ad infrastructure, showcasing the attackers’ methodical approach.

Technical overview of the IP addresses and domains

The IP addresses involved, 185.11.61.243 and 185.147.124.110, have seen consistent activity with multiple unique domains mapped to them. The first IP address has been active since July 29, hosting over 109 unique domains. Meanwhile, the second IP started its operations on November 25, 2024, and is currently linked to 85 unique domains designed to distribute malware.

On November 14, 2024, a campaign launched on frecadsolutions.cc, utilizing Bitbucket for file hosting. The pattern continued with the appearance of freecad-solutions.net on November 26, which initially linked back to the first IP but later migrated to the second. This illustrates a coordinated effort among the attackers to maintain their operations despite attempting to conceal their tracks through IP switching.

A series of campaigns continued into December, activating domains like rhino3dsolutions.net and planner5design.net, which saw their hosting migrated between the two malicious IPs. The ongoing nature of these attacks raises concerns over the effectiveness of current protective measures against such sophisticated malvertising schemes.

As for the nature of the threats posed, recent reports suggest that these individuals may also exploit vulnerabilities in web browsers and ad networks, increasing the risk for users who inadvertently click on these ads. The scale and persistence of these campaigns underscore a need for vigilance among graphic design professionals and the general public alike.


Featured image credit: Pankaj Patel/Unsplash

Related Posts

Twitch debuts live-shopping tech powered by Amazon Ads and e.l.f.

Twitch debuts live-shopping tech powered by Amazon Ads and e.l.f.

October 17, 2025
Amazon One Medical offers pay-per-visit kids’ virtual care

Amazon One Medical offers pay-per-visit kids’ virtual care

October 17, 2025
Spotify partners with record labels to build “responsible AI” music tools

Spotify partners with record labels to build “responsible AI” music tools

October 17, 2025
Pinterest responds to “AI slop” backlash with new filtering tools

Pinterest responds to “AI slop” backlash with new filtering tools

October 17, 2025
Meta Messenger desktop apps reach end of life in December

Meta Messenger desktop apps reach end of life in December

October 17, 2025
Reddit expands AI-powered search to five new languages

Reddit expands AI-powered search to five new languages

October 17, 2025

LATEST NEWS

Twitch debuts live-shopping tech powered by Amazon Ads and e.l.f.

Amazon One Medical offers pay-per-visit kids’ virtual care

Spotify partners with record labels to build “responsible AI” music tools

Pinterest responds to “AI slop” backlash with new filtering tools

Meta Messenger desktop apps reach end of life in December

Reddit expands AI-powered search to five new languages

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.