AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接写描述。 首先,我需要快速浏览文章内容。文章讲的是网络犯罪分子利用SEO和AI生成内容进行广告欺诈。他们通过Google的Discover功能推送虚假新闻,诱骗用户开启浏览器通知,进而传播 scareware 和金融诈骗。 接下来,我需要提取关键点:广告欺诈、SEO和AI技术、Google Discover、虚假新闻、浏览器通知、scareware和金融诈骗。还有提到该活动影响广泛,涉及多个地区,并且Google已经采取措施修复。 现在,我要把这些信息浓缩到100字以内。确保涵盖主要的技术手段、目标平台、影响范围以及后果。同时,保持语言简洁明了。 最后,检查字数是否符合要求,并确保信息准确无误。 </think> 网络犯罪分子利用SEO技术和AI生成内容,在Google Discover中推送虚假新闻,诱骗用户开启浏览器通知并点击恶意链接,导致 scareware 和金融诈骗。该活动已影响印度、美国等多国,并通过Google修复漏洞得以缓解。 2026-4-14 14:30:0 Author: thehackernews.com(查看原文) 阅读量:3 收藏

Ad Fraud / Artificial Intelligence

Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google's Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams.

The campaign, which has been found to target the personalized content feeds of Android and Chrome users, has been codenamed Pushpaganda by HUMAN's Satori Threat Intelligence and Research Team.

"This operation, named for push notifications central to the scheme, generates invalid organic traffic from real mobile devices by tricking users into subscribing to enabling notifications that presented alarming messages," researchers Louisa Abel, Vikas Parthasarathy, João Santos, and Adam Sell said in a report shared with The Hacker News.

At its peak, about 240 million bid requests have been associated with 113 domains linked to the campaign over a seven-day period. The threat, although observed targeting India, has since expanded to other regions like the U.S., Australia, Canada, South Africa, and the U.K.

The findings demonstrate how threat actors abuse AI to hijack trusted discovery surfaces and turn them into delivery vehicles for scareware, deepfakes, and financial fraud, Gavin Reid, chief information security officer at HUMAN, said. Google has since rolled out a fix to address the spam issue.

The entire scheme hinges on the scammers luring unsuspecting users through Google Discover to trick them into visiting misleading news stories filled with AI-generated content. Once a user lands on one of the actor-controlled domains, they are coerced into enabling push notifications that deliver fake legal threats and scams.

Specifically, the scareware notifications, once clicked, redirect users to additional sites operated by the threat actors, generating organic traffic to ads embedded in those sites and enabling them to generate illicit revenue.

This is not the first time threat actors have weaponized push notifications to redirect to sketchy websites. In September 2025, Infoblox shed light on a threat actor known as Vane Viper that has engaged in systematic push notification abuse to serve ads and facilitate ClickFix-style social engineering campaigns.

"Malware-based threats involving push notifications, both for web and mobile platforms, aren't a novel threat, especially when you consider the way in which they create a sense or urgency," Lindsay Kaye, vice president of threat intelligence at HUMAN Security, told The Hacker News. "In many cases, users are quick to click, either to make them go away or to get more information, making them an effective tool in a malware author's arsenal."

The disclosure also comes a little over a month after HUMAN identified a collection of more than 3,000 domains and 63 Android apps that it said constituted one of the largest ad fraud laundering marketplaces ever uncovered. Dubbed Low5 for its use of HTML5-based game and news sites, the operation has been found to monetize the domains as cashout sites for sophisticated fraud schemes, including BADBOX 2.0.

"The operation peaked at roughly 2 billion bid requests a day and may have operated on as many as 40 million devices worldwide," the company said. "Apps associated with Low5 include code that instructs user devices to visit one of the domains connected with the scheme and click on ads found there."

Cashout sites, also called ghost sites, are used to conduct content-driven fraud, where the attackers use bogus sites and apps to sell space to advertisers who may assume their ads will be viewed by humans. The Android apps in question have been removed from the Google Play Store.

"A shared monetization layer spanning more than 3,000 domains allows multiple threat actors to plug into the same infrastructure, creating a distributed laundering system that increases threat resilience, complicates attribution, and enables rapid replication," HUMAN added.

"A key takeaway from this research is that monetization infrastructure can survive even after a specific fraud campaign is shut down. If one malicious app or device network is removed, the same cashout domains can still be reused by other actors. Low5 reinforces the need for continuous, aggressive threat intelligence and detection expertise to hunt down cashout domains and flag them pre-bid."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/ai-driven-pushpaganda-scam-exploits.html
如有侵权请联系:admin#unsafe.sh