Skip to main content

Netskope Threat Labs details a Google Ads-delivered fake security locker

49th article in the last 90 days, one of 291 articles referencing Netskope. Previous coverage: Google details how Gemini reached real organizations during Irregular test (Sep 2026).

Companies mentioned

Best suited for

Seniority
Director
Job function
Cybersecurity / Security Operations
Persona
Security Operations Practitioner
Buyer role
Technical Implementer / Administrator
Buyer journey
Open to Buy
Adoption curve
Early Majority
Technology maturity
Operational Expansion
Industry
Information Technology / Cybersecurity / Endpoint, Email & Data Security / Endpoint Security (EPP/EDR/XDR)

Our classification, not the publisher's statement. Best suited for, not only for.

Netskope Threat Labs reports tracking a cloud-hosted tech-support-scam kit that uses a mouse-movement gate, runtime decryption, and a full-screen “security” lockout page to pressure victims into calling a number. The report is relevant to enterprise IT and security teams because it combines ad-driven delivery with browser-resident payload execution and anti-analysis techniques.

Research Overview

The report describes a tech-support-scam (TSS) activity where victims click a Google ad and reach a loading spinner page that later presents an online store interface branded “ShopEase.” Netskope states that flagged URLs mirrored this appearance and that the transition occurred only after attempting to click the button under the spinner.

Threat Labs says the scam is hosted in the cloud and hijacks the victim’s browser to display fake security messaging, including an operating-system-specific workflow and a callback number. The goal, according to the report, is either to extract payment for fake support, gain remote access, or collect personal and financial details.

Key Findings

Netskope highlights a bot-filtering mechanism that waits for a single mouse movement before any further actions run. After the movement is detected, the kit decrypts a hidden C2 address, fetches an encrypted payload, and decrypts a platform-specific locker component for Windows or macOS.

The report says the decrypted locker is assembled and displayed from browser memory rather than loaded as an inspectable file over the network. It also notes a fallback behavior in which the kit stops if the C2 is unavailable or if decryption fails, leaving the storefront visible.

Technical Breakdown

Threat Labs describes two decryption stages using hardcoded keys embedded in the page. First, it decrypts a hidden string to recover a live C2 address, then it fetches a “locker” from that C2 and decrypts it into a Windows or macOS variant.

For victim interaction, the report states the locker initiates full-screen mode using requestFullscreen() after the first click anywhere, hiding the address bar and tabs. It further says the kit hides the mouse cursor, attempts to swallow Escape and other exit shortcuts via the browser keyboard-lock API, and degrades browser responsiveness through alert sounds on interaction and busy loops.

Operational Impact

Netskope attributes most traffic to Google Ads and points to ad-tag parameters such as gclid, gad_source, and gad_campaignid observed on the scam URLs. It states that these parameters indicate ad-click attribution and that the clicks use Google’s click-redirect domain googleads.g.doubleclick.net.

In a two-week period from August 31 to September 14, 2026, the report says the kit hit at least 619 organizations. Threat Labs reports that the United States accounts for roughly 62% of affected organizations, Japan 16%, and Australia 14%, with other countries making up the remainder.

Delivery Details

The report says referrer analysis pointed to high-traffic maps, weather, real-estate, document-hosting, and sports sites, while stating those publishers were not compromised and that the ads ran through normal inventory. It also reports tracking more than 250 Google Ads campaign IDs across at least 284 publisher sites.

Netskope reports counting 457 scam hosts over the same two-week window and provides totals for cumulative affected organizations and scam hosts. It frames the activity as a moving target because operators rotate infrastructure and reskin the decoy storefront.

Leadership Perspective

In Netskope’s assessment, the observed runtime-decryption and anti-analysis behavior reflects tradecraft used in more sophisticated web threats referenced in the report, including a Barracuda example called “CypherLoc.” The report ties the user impact to the full-screen locker that hides cursor controls, swallows exit shortcuts, and creates lag to reinforce the fake alert.

Netskope says its Threat Protection detects the kit inline as “Generic.Phishing Tech Support Scam Kit Detected.” Threat Labs reports continuing to monitor the campaign, expanding coverage across variants, and monitoring for other similar cloud-hosted TSS kits as they emerge.

Overall, the Netskope Threat Labs report describes an ad-delivered browser-based tech-support-scam kit that gates execution on mouse movement, decrypts and renders a platform-specific “locker” from browser memory, and presents a full-screen fake warning intended to push victims toward a phone number. Blog Signals brief is a fact-based summary of the vendor blog.

Blog post, originally published by John Carlo Marquez at netskope.com.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/netskope-threat-labs-details-a-google-ads-delivered-fake-security-locker/",
        "name": "Netskope Threat Labs details a Google Ads-delivered fake security locker",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/netskope-threat-labs-details-a-google-ads-delivered-fake-security-locker/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@id": "https://decisioninsights.ai/registry/netskope/#organization",
      "@type": "Organization",
      "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
      "name": "Netskope"
    },
    "articleSection": [
      "Cybersecurity"
    ],
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Director"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Security Operations"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Practitioner"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Technical Implementer / Administrator"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Early Majority"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Operational Expansion"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Cybersecurity / Endpoint, Email & Data Security / Endpoint Security (EPP/EDR/XDR)"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-coverage/#person",
      "@type": "Person",
      "name": "Decision Insights Coverage",
      "url": "https://decisioninsights.ai/author/decision-insights-coverage/"
    },
    "dateModified": "2026-09-24T13:43:40-06:00",
    "datePublished": "2026-09-24T13:43:34-06:00",
    "description": "Netskope Threat Labs reports a cloud-hosted tech-support-scam kit that uses a mouse-movement gate, runtime decryption, and full-screen fake alerts.",
    "headline": "Netskope Threat Labs details a Google Ads-delivered fake security locker",
    "isBasedOn": {
      "@type": "CreativeWork",
      "author": {
        "@type": "Person",
        "name": "John Carlo Marquez"
      },
      "sourceOrganization": {
        "@id": "https://decisioninsights.ai/registry/netskope/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
        "name": "Netskope"
      },
      "url": "https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads"
    },
    "keywords": [
      "Threats"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/netskope-threat-labs-details-a-google-ads-delivered-fake-security-locker/",
      "@type": "WebPage",
      "sdDatePublished": "2026-09-24",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/netskope/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
        "name": "Netskope"
      },
      {
        "@id": "https://decisioninsights.ai/projects/perspective/#project",
        "@type": "SoftwareSourceCode",
        "mainEntityOfPage": "https://decisioninsights.ai/projects/perspective/",
        "name": "Perspective"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-coverage/#person",
    "@type": "Person",
    "description": "Blog posts, podcasts, and video analysis from across the industry, condensed into short, sourced summaries. Produced under our Standards & Methodology.",
    "name": "Decision Insights Coverage",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-coverage/"
  }
]

Is this your company? Get structured data for your own pages