Description

Beware of a sophisticated phishing scam targeting users searching for the decentralized OTC trading platform "Whales Market" on Google. A legitimate-looking Google ad for Whales Market, displaying the URL www.whales.market, redirects users to a phishing site at https://app.whaless[.]market/. Note the extra "s" in the domain name. The phishing site closely replicates the legitimate Whales Market website, including its trading platform. However, once you connect your wallet, malicious scripts will drain it of all assets. It's essential to verify the domain displayed in your browser's address bar before connecting your wallet to any Web3 website. This scam underscores a broader issue with Google Ads, as threat actors have been abusing the platform to distribute malware or redirect users to phishing sites and tech support scams for years. While many malicious ads contain obvious typos or extra characters in the domain, others display legitimate URLs for impersonated platforms, making them harder to detect. Threat actors exploit a loophole by redirecting visitors based on their IP address or browser user agent. When Google's search bots verify the site, they are redirected to the legitimate website being promoted, tricking the ad platform into approving the URL. However, regular users clicking on these ads are instead redirected to malicious sites. This method has affected not only Google but also Microsoft and X ad platforms. Despite efforts to prevent such ads from slipping through, the issue persists. Be vigilant and always verify website URLs before entering any sensitive information.