Bfore.AI Blog, Blog
Brand Impersonated Search Engine Advertisements | Bfore.AI
For years threat actors have used social engineering (SE) techniques to trick victims into revealing sensitive personal information for identity and monetary theft. One of the most well-known tactics used within SE is phishing, wherein victims are contacted through online messaging platforms from seemingly reputable organizations encouraging the victim to either download a file or click on a link. To avoid this, cybersecurity companies generally advise individuals to use a search engine (such as Google or Bing) to find the website they are looking for rather than clicking on a link in a suspicious email.
With individuals becoming more knowledgeable of phishing emails and how to identify them, threat actors have needed to find an alternate way of luring victims to their malicious websites. Since users, whether attempting to avoid a phishing email or not, generally use search engines to find almost everything they need, threat actors have increasingly started exploiting this sphere. They do so by impersonating brands in advertisements that appear in search engine results, such as in the screenshot below showing a brand-impersonated search engine advertisement of the password manager, Bitwarden.

The two search results look very similar. However, the URLs are pretty different:

How do these brand impersonation scams work?
Brand impersonation is often deployed by threat actors, using a brand’s logo, colors, font, and so on to ensure recognition and inspire trust with victims. As brands today all have some form of online presence (websites, mobile applications, social media accounts), replicating and impersonating a brand is a relatively simple task for threat actors.
In these attacks, threat actors will have registered a domain similar to the targeted corporation before creating a fake website that, through brand impersonation, looks genuine and similar to the legitimate site, if not a complete clone. They then use a search engine to buy advertisement spacing by creating a search campaign. For example, Google’s pay-per-click (PPC) Ads platform has been frequently used in these attacks. So, when a user searches for a company or a service via a search engine, these advertisements will be displayed at the top of search results, often showcasing minimal distinction between the brand-impersonated advertisement and the actual search result—an easy way to fool users.
Once a user clicks on the fake advertisement, they are directed to the brand’s impersonated website. These websites will pose different threats depending on the attacker’s end goal.


Prevent the next Cyber Threat
Bfore.AI patented AI technology combined with hyperscale observation infrastructure and modern APIs augment our customers security postures with Predictions.
Discover Predictive Cyber-Security
Book a live demo with our specialist to discover how Bfore.AI helps organization fight cyber threats with their patented technology.



