Cybercriminals have recently manipulated Google search advertisements to deliver harmful software via ads that appear to promote the well-known communication platform Slack.
This covert and advanced attack illustrates how threat actors are refining their methods to circumvent security protocols and avoid detection.
Surge in Malvertising Cases
In the last year, around 500 distinct incidents involving malvertising through Google search ads have been documented. Many of these cases exhibit patterns indicative of organized efforts by malicious entities.
Some perpetrators use elaborate strategies to evade security defenses, while others are prepared to sacrifice their accounts and infrastructure to achieve their aims. The attack on Slack is particularly notable for its subtlety and advanced tactics.

Context and Red Flags in Ads
For several days, a dubious Slack ad was prominently displayed in Google search results. Although it initially appeared credible, directing users to Slack’s legitimate website, a closer look revealed inconsistencies. The ad was placed among other products seemingly aimed at the Asian market, which was incongruous and suspicious.

This discrepancy underscored the necessity of contextual analysis in detecting compromised ad accounts.
The Gradual Deception Technique
Initially, the Slack ad led users to a pricing page on Slack’s official site. This gradual approach, known as “slow cooking,” is a strategy used by malicious actors to avoid quick detection by allowing the ad to stay hidden for a while.
Eventually, the ad’s destination shifted, redirecting users to a click tracker—an exploit within the Google ad system used to filter clicks and redirect users to harmful sites.

The final URL redirected users to slack-windows-download[.]com, a domain that was created just days before. Although it initially seemed legitimate, further scrutiny revealed a malicious site masquerading as Slack and offering a harmful download link.
This approach, known as cloaking, involves presenting different content to different users, complicating the detection of malicious activities without specialized tools and knowledge of the attackers’ tactics, techniques, and procedures (TTPs).
The Malicious Payload
The download button on the malicious page prompted a file download from another domain, hinting at a parallel operation targeting Zoom.
Dynamic analysis in a sandbox environment revealed a connection to a server linked with SecTopRAT, a remote access Trojan known for its stealing capabilities. This malware has been involved in various malvertising campaigns, including those imitating NordVPN.
In response, cybersecurity firm Malwarebytes has upgraded its detection measures and reported the fraudulent ad to Google. Cloudflare has also marked the deceptive domains as phishing threats.
Despite these interventions, cybercriminals continue to exploit both free and paid platforms to avoid detection, showing their persistence and strategic foresight.
As cyber threats grow more sophisticated, it’s crucial for individuals and organizations to stay alert and informed. Users should exercise caution when interacting with ads and verify the authenticity of websites before downloading files.
By remaining vigilant and implementing proactive security practices, we can better shield ourselves from the ever-evolving threats in the cyber landscape.



