Zscaler exposes Ledger phishing chain built on Google Ads and cloud services
Since at least August 2026, attackers have run fake Ledger ads through Google Ads and routed victims through a chain of Google Cloud Storage, Vercel and Google Sites pages that ask for the 24-word seed phrase. Every hop sits on a trusted domain, so URL-reputation filters never fire; Zscaler ThreatLabz published the analysis on September 25.
- Fake Ledger ads run via a verified Google Ads account registered in Germany
- Redirect chain: Google Cloud Storage → Vercel → Google Sites, with subdomains rotating every 15–20 minutes
- The page mimics Ledger setup and requests the 24-word seed phrase with BIP-39 autocomplete
- An invisible hCaptcha filters out security scanners to extend the campaign's lifespan
Read next
Security