New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support Scam Kit
A new cybersecurity threat has been identified within the digital advertising ecosystem, specifically targeting users through Facebook’s paid advertising platform.
A new cybersecurity threat has been identified within the digital advertising ecosystem, specifically targeting users through Facebook’s paid advertising platform.
Malicious actors are utilizing social media ads to bypass traditional security filters and deliver harmful content to unsuspecting users.
This recent campaign employs a three-step malvertising chain to deceive users and redirect them to a technical support scam (TSS) kit, posing a significant risk to cybersecurity.
The attack begins when a user interacts with a paid advertisement. Instead of directing to a legitimate site, the ad initiates a redirection sequence.
The user is first routed to a decoy website resembling an Italian restaurant page, serving as a buffer to evade detection. The user is then redirected to a fraudulent landing page designed to alarm and deceive them.
Malicious actors are utilizing social media ads to bypass traditional security filters and deliver harmful content to unsuspecting users.
The campaign exclusively targets users in the United States. To maintain persistence and avoid detection, attackers rotated through over 100 domains within seven days, primarily operating on weekdays to align with peak usage hours.
The final stage involves a landing page hosted on Microsoft Azure’s cloud infrastructure. By using legitimate subdomains like web.core.windows.net , scammers create a facade of authenticity.
These pages mimic official system warnings, falsely claiming device compromise to coerce users into contacting a fake support hotline.
Evasion Through Legitimate Infrastructure
The campaign's defining feature is its use of trusted cloud services to mask malicious intent. Hosting TSS landing pages on Azure complicates mitigation, as blocking the core Windows domain would disrupt valid services.
The use of simplydeliciouspairing[.]com further obfuscates the attack flow, ensuring only real browser interactions reach the scam kit. This strategy, combined with domain rotation, allows the campaign to evade static blocklists and signature-based detection.
Users are advised to exercise caution when interacting with social media advertisements. Verify URL destinations and be cautious of unexpected redirects.
Security teams should implement blocks for identified indicators of compromise (IOCs) and monitor for anomalous traffic patterns involving Azure subdomains.
Based on reporting by Cyber Security News.
