3 ms·
Wow, this is a remarkably simple ploy from the scammers. Combining Google's own ad account policies to serve a Display URL of ads.google.com, and a Google hoste
by Festro 2y ago
Wow, this is a remarkably simple ploy from the scammers. Combining Google's own ad account policies to serve a Display URL of ads.google.com, and a Google hosted microsite on sites.google.com to get past the automated ad approvals and pose as Google in their own ad results.
Should be a fairly simple fix for Google to blacklist sites.google.com from their ad tools, though perhaps they want to let people spin up ads on microsites like that as a boostrapped way of running ads without their own site?
To be fair they probably should blacklist any mention of Google in an ad and use a Brand registry to manually verify anyone who wants to use their trademark in ad URLs or copy.
- semking 2y agoYes, the "trick" is ultra-simple: to fool Google, the scammers host the initial malicious code on the sites.google.com subdomain, allowing them to display the official ads.google.com subdomain... peek irony if you ask me! :) Google didn't care until now. We reported hundreds of ads. I hope this content will push them to react. But there's another problem we've noticed in the past 24 hours: major legit ad accounts are being compromised.