A sophisticated phishing operation is specifically targeting SEO professionals through malicious Google Ads that impersonate Semrush, the popular SEO and marketing platform. Security researchers from Malwarebytes, including Jerome Segura, along with SEO strategist Elie Berreby, have identified this campaign as part of a growing trend of “cascading fraud” operations.
## The Attack Strategy
When users search for Semrush-related terms, they encounter sponsored Google Ads that lead to convincing phishing sites with domain names like “semrush.click,” “semrush.tech,” and “sem-rushh.com.” These fake sites mimic Semrush’s interface but only offer “Log in with Google” as an authentication option, forcing visitors to surrender their Google credentials.
The researchers believe a Brazilian threat group is behind this campaign, with their primary target being Google Ads accounts that can be leveraged to launch additional malvertising campaigns. The attackers are also interested in SaaS platform credentials, particularly those integrated with Google services.
## Why Semrush Users Are Valuable Targets
Semrush is used by digital marketers, advertisers, and 40% of Fortune 500 companies. Its integration with Google Analytics and Google Search Console means users often link valuable Google accounts containing sensitive business data, including:
– Revenue metrics
– Marketing strategies
– Customer behavior analytics
“If an enterprise Google account was linked in the past, there’s a possibility of exfiltrating sensitive Google data without compromising the Google account itself,” explained Berreby to BleepingComputer.
## Google’s Response to Malvertising
While Google has responded quickly to take down the malicious ads from this specific campaign, Berreby notes that addressing the broader issue requires higher-level decisions within Google.
“The problem is the people we talk with at Google cannot address the underlying issues because they are not decision-makers,” Berreby stated. “They are diligently doing their best at an individual level, but that’s not enough, and frankly, that’s not acceptable for a giant tech company like Google.”
## Protection Recommendations
To avoid falling victim to such scams:
– Avoid clicking on sponsored/promoted search results
– Bookmark frequently accessed pages for direct visits
– Verify domain names before entering credentials
– Use password managers that will only autofill on legitimate domains
This campaign highlights the evolving sophistication of phishing attacks that leverage trusted brands and legitimate advertising platforms to target business professionals.
