Researchers say they recently found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices and displays messages urgently instructing them to phone a bogus call center.
The ads were displayed all over the Web, including on high-traffic maps, weather, real-estate, document-hosting, and sports sites. Users who called the number were then urged to pay hefty fees, grant remote access to their devices, or divulge personal information. From August 31 to September 14, security firm Netskope observed users from 619 customer organizations click on the malicious ads, although none of them were actually scammed because Netskope blocked the content.
Roughly 62 percent of the organizations were based in the US, with Japan and Australia accounting for the Nos. 2 and 3 spots. Since the firm has visibility into only a tiny sliver of Internet activity, the number of people exposed to the ads—including those who fell victim to it—is likely much higher. Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites.
So, what about Uncle Louie?
“For the victim, that tradecraft turns an ordinary ad click into a browser that appears to seize up on a fake security warning,” Netskope said. “The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen. Nothing on the computer is actually locked, but in the moment it is convincing enough to push people toward the scam.”
By now, many people, including a fair number of readers of this site, ridicule and shame people who fall for such scams. These criticisms fail to account for a sizable portion of Internet users who have little or no understanding of how computers and the Internet work. Combined with their need to get things done quickly and the growing difficulty of navigating the Web, this lack of awareness makes a sizable portion of users prime targets. There’s little doubt some critics have close friends and family who are among those who simply don’t know enough to be wary.
Further making the scam convincing, the software kit that delivers the fake warnings is designed to be stealthy and closely mimic the signs of a real infection. The browser address bar no longer appears, the warning screen occupies the entire screen, and presses of escape and many other keys are disabled. The browser performance degrades, sounds play, and pages lag, giving the impression something is seriously wrong. Messages urging the user to not to restart the machine and call a call center immediately flash. Attempts to close the browser only makes the scam message refresh.
The warnings appear only after a user makes a mouse movement. The software is also encrypted and only decrypted and then displayed in browser memory. Both these conditions prevent many endpoint security wares—and possibly Google’s own ad filters—from detecting the malice. Further, the warning ads appear differently depending on whether the targeted user device is running Windows or macOS.
Google didn’t say what caused its scanners to miss the scam campaign or give any indication the ads have been fully removed from its massive ad platform.
“We have zero tolerance for scams,” the company said in a statement. “We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.” The company has said that last year it blocked over 99 percent of violating ads before they ever served.
As Netskope noted, devices aren’t actually locked up, even though most of the usual keys for closing the scam window have been disabled. In this case and many similar ones, users can still easily exit the window. For both Windows and macOS devices, this can be done in most cases by pressing the escape key and holding it for several seconds. The press will force the browser out of full screen and release the keyboard lock, and from there the tab can be closed. An alternative approach is to invoke the Windows Task Manager (control-shift-escap) and exit the browser. On a Mac the keys are (cmd-option-escape). In both cases, users can reopen the browser without restoring the previous session.
No legitimate company will ever advise users to call a phone number when they’re infected. Under no case should people hit by tech support scams call the number. Those who provide informal tech support for friends and family might consider writing the above advice on a Post-it and affixing it to screens.







