Malware ads on Google Ads
Archived — this story has rotated out of today’s deck. It is kept here in full.
The gist
Researchers found deceptive Google ads reaching millions, with Google ruling 15 of 24 reported ads non-violating.
The findings raise questions about ad-platform moderation and who bears the risk when bad.
Background
Multiple 2026 reports describe malicious or deceptive advertising slipping through major ad platforms. Researchers pulled data from Google's own Ads Transparency Center in the EEA and used Google's Gemma AI to analyze ads, then reported a sample to Google to test moderation. Separately, a macOS developer said his Google Ads account was suspended for 'Malicious software' and 'Compromised Site' despite clean scans, and appeals were repeatedly rejected. Other campaigns used Meta, TikTok and Facebook ads to push malware or scam pages.
How it unfolded
- Jul 2025Check Point first documents JSCeal malware, spread via fake cryptocurrency trading sites reached through malicious ads on Facebook and Google.
- Sep 3, 2026Cybernews reports researchers found thousands of deceptive Google ads using Google's own free AI tools; of 24 ads reported to Google, only 6 were confirmed as violations, 3 were 'unable to review,' and 15 were ruled non-violating.
- Sep 3, 2026Malwarebytes reports StreamRat Android malware spreading through Meta and TikTok ads, advising users to avoid installing apps from ads or sponsored search results.
- Sep 7, 2026The Hacker News reports JSCeal can bypass Google authentication using stolen session cookies, noting the malware was spread via malicious ads on Facebook and Google.
- Sep 9, 2026A developer publishes an account of his Google Ads account being suspended for 'Malicious software' and 'Compromised Site' after spending $500, with repeated appeals rejected despite clean Google Safe Browsing, VirusTotal and Search Console results.
Who’s saying what
- Researchers
- Cybernews-quoted researcher Roongta said the moderation results were surprising and point to real gaps in how Google handles reported ads.
- Developer
- The RACE developer argues the suspension may be a false positive, possibly tied to legitimate subprocess-management behavior inherent to a terminal multiplexer.
- Security Firm
- Malwarebytes advises downloading apps through Google Play and avoiding installs from ads, direct-download sites, social media messages or sponsored search results.
Still unverified
The RACE developer's claim that the suspension was a false positive is his own account and has not been independently confirmed by Google. The exact cause of the suspension is unknown. The Cybernews finding that 15 of 24 reported ads were ruled non-violating is based on the researchers' own reporting to Google and has not been independently verified.