Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Further making the scam convincing, the software kit that delivers the fake warnings is designed to be stealthy and closely mimic the signs of a real infection. The browser address bar no longer appears, the warning screen occupies the entire screen, and presses of escape and many other keys are disabled. The browser performance degrades, sounds play, and pages lag, giving the impression that something is seriously wrong. Messages urging the user not to restart the machine and to call a call center immediately flash. Attempts to close the browser only make the scam message refresh.
The warnings appear only after a user makes a mouse movement. The software is also encrypted and only decrypted and then displayed in the browser memory. Both these conditions prevent many endpoint security wares—and possibly Google’s ad filters—from detecting the malice. Further, the warning ads appear differently depending on whether the targeted user device is running Windows or macOS.
Google didn’t say what caused its scanners to miss the scam campaign or give any indication the ads have been fully removed from its massive ad platform.
“We have zero tolerance for scams,” the company said in a statement. “We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.” The company has said that last year it blocked over 99 percent of violating ads before they were ever served.
As Netskope noted, devices aren’t actually locked up, even though most of the usual keys for closing the scam window have been disabled. In this case and many similar ones, users can still easily exit the window. For both Windows and macOS devices, this can be done in most cases by pressing the escape key and holding it for several seconds. The press will force the browser out of full screen and release the keyboard lock, and from there, the tab can be closed. An alternative approach is to invoke the Windows Task Manager (control-shift-escape) and exit the browser. On a Mac, the keys are (cmd-option-escape). In both cases, users can reopen the browser without restoring the previous session.
No legitimate company will ever advise users to call a phone number when they’re infected. Under no case should people hit by tech support scams call the number. Those who provide informal tech support for friends and family might consider writing the above advice on a Post-it and affixing it to screens.
