Google Ads A.I CyberSecurity Scoring
Google Ads
Company Information
Website:http://g.co/ads/aiessentials
Employees number:11
Number of followers:903,306
NAICS:541613
Industry Type:Advertising Services
Homepage:g.co
Google Ads Risk Score (AI oriented)
Between 650 and 699
Google AdsAdvertising Services
Updated:
29/07/2026
29/07/2026
693/1000
Weak
B
Google Ads Global Score (TPRM)
xxxx
Google AdsAdvertising Services
Score locked

Google AdsWeak
Current Score
693B (WEAK)
01000
2 incidents
-27 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
695
AUGUST 2026
693
JULY 2026
693
JUNE 2026
691
MAY 2026
687
APRIL 2026
687
MARCH 2026
685
FEBRUARY 2026
709
Cyber Attack
14 Feb 2026 • Google Ads
Anthropic, Google, Medium and Apple: Malicious Campaign Uses Claude Artifacts and Google Ads to Deliver macOS Malware
Sophisticated macOS Malware Campaign Exploits Google Ads, Claude AI, and Medium to Distribute MacSync Stealer
682
CRITICAL-27
ANTGOOAPPMED1771064819
Sophisticated macOS Malware Campaign Exploits Google Ads, Claude AI, and Medium to Distribute MacSync Stealer
A recent malware campaign is targeting macOS users through a multi-pronged attack leveraging sponsored Google search results, Claude AI’s public artifact feature, and fraudulent Medium articles. The operation, uncovered by cybersecurity researchers at Moonlock Lab, has exposed over 15,000 users to the MacSync information stealer, which siphons sensitive data including keychain credentials, browser data, and cryptocurrency wallets.
The campaign employs two distinct variants, both using the ClickFix social engineering technique to deceive users into executing malicious commands.
### First Variant: Fake DNS Resolver via Claude AI
When users search for "Online DNS resolver" on Google, a sponsored result directs them to a public Claude AI artifact titled "macOS Secure Command Execution." The fake guide masquerades as a legitimate security tool, instructing victims to paste a base64-encoded command into their Terminal. Upon execution, the command downloads a loader for MacSync from `/tmp/osalogging.zip`, which then establishes communication with a command-and-control (C2) server at `a2abotnet[.]com/dynamic`.
The malware uses a hardcoded authentication token and API key, spoofs a macOS browser User-Agent string to evade detection, and exfiltrates stolen data via Apple’s `osascript` utility. Larger datasets are uploaded in chunks with retry mechanisms and exponential backoff to ensure successful transmission. After exfiltration, the malware deletes staging files to cover its tracks.
### Second Variant: Fake Disk Space Analyzer via Medium
A second attack vector targets users searching for "macOS CLI disk space analyzer" through a fraudulent Medium article hosted at `apple-mac-disk-space.medium[.]com`. The article impersonates Apple’s official Support Team and delivers a similar ClickFix payload with additional obfuscation, including string concatenation tricks (e.g., `cur””l`) to bypass detection. The malicious payload is fetched from `raxelpak[.]com`.
### Evasion Tactics and Broader Implications
The threat actors behind this campaign demonstrate a deep understanding of social engineering and evasion techniques, exploiting trusted platforms like Google Ads, Claude AI, and Medium to lend legitimacy to their attacks. By abusing these services, they bypass traditional security controls and reach a broader audience.
The MacSync stealer remains a persistent threat, with its operators continuously refining their methods to avoid detection while maximizing data theft. The campaign underscores the growing trend of malware distributors leveraging legitimate services to propagate malicious payloads.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
708
DECEMBER 2025
707
NOVEMBER 2025
705
OCTOBER 2025
704
JULY 2025
753
Cyber Attack
01 Jul 2025 • Google Ads
Google: Stolen Meta and Google ad accounts are worth more than the money they hold
Cybercriminals Turn Ad Account Theft into a Lucrative Underground Economy
698
CRITICAL-55
GOO1785321058
Cybercriminals Turn Ad Account Theft into a Lucrative Underground Economy
Cybercriminals have transformed the hijacking of Meta Business Manager and Google Ads accounts into a structured, commodity-driven market, complete with tiered pricing, escrow services, and money-back guarantees for stolen credentials. While drained ad budgets are often the most visible consequence, the real value for attackers lies in aged, high-spending accounts which bypass platform security checks and command premium prices in underground forums.
According to Mimecast, compromised accounts with established spending histories and verification statuses sell for 2–4 times more than newly created ones. Zscaler reports stolen Meta Business Manager accounts fetching $15–$340, while high-risk Google Ads accounts have been listed for $200–$270 on Telegram. Pricing depends on factors like account age, daily spending limits, and past ad performance.
### A Rising Threat Despite Crackdowns
Mimecast’s four-year telemetry reveals 6.4 million detections of ad account theft, with 1.86 million recorded in the second half of 2025 a record high, despite recent enforcement actions. Takedowns, such as the March 2026 dismantling of the PXA Stealer ring (which led to 14 prosecutions), only caused temporary dips before activity rebounded.
The campaigns are linked to Vietnam-based malware families (DuckTail, NodeStealer, VietCredCare, PXA Stealer) as well as operations from Brazil, Portugal, China, and Hong Kong.
### How Attackers Bypass Security Filters
Rather than relying on malicious infrastructure, cybercriminals exploit trusted platforms to evade detection. Mimecast found that:
- One-third of detections arrived via Salesforce infrastructure
- A quarter used Google Workspace mail-merge tools or SharePoint-hosted links
These services provide legitimate sender reputations, allowing phishing emails to bypass SPF, DKIM, and IP-based filters. Attackers only need to craft convincing content to trick victims.
### The Long-Term Cost of Account Theft
While fraudulent ad spend can be halted within hours, recovering a hijacked account is far more difficult. Attackers often add their own admins and downgrade legitimate owners, leaving victims locked in appeal queues for months. Unlike credit card fraud, ad platforms lack zero-liability protections, and their revenue models incentivize delayed responses since compromised accounts continue generating ad impressions (and platform revenue) even under review.
A 2026 class-action lawsuit by the Consumer Federation of America alleges Meta’s scam advertising ecosystem generates 15 billion fraudulent impressions daily, worth an estimated $7 billion annually. While Meta has taken legal action against scam advertisers, critics argue platforms prioritize revenue over swift account recovery.
Until advertisers treat ad accounts with the same security rigor as other high-value assets and platforms improve recovery processes stolen accounts will remain a persistent threat in the cybercriminal economy.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Google Ads ??
What was Google Ads's A.I Rankiteo Cyber Score in August 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in July 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in June 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in May 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in April 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in March 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in February 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in January 2026 ??
What was Google Ads's A.I Rankiteo Cyber Score in December 2025 ??
What was Google Ads's A.I Rankiteo Cyber Score in November 2025 ??
What was Google Ads's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Google Ads's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Google Ads ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Google Ads's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?