Threat Actors Use Google Ads To Target Ledger Users
Brief
IntroductionIn August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes.
There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices. In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases.
Key TakeawaysIn August 2026, ThreatLabz discovered a campaign in which fraudulent Google ads targeting Ledger users appeared under a Google-verified advertiser profile.
