Google served me Malware

Google served me Malware

🎙 John Hammond 👥 2.2M 📅 May 27, 2026 ⏱ 25 min 👁 224K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

malvertisingGoogle Adsmalware analysisphishing kitDLL side-loading

Summary

John Hammond investigates a malware distribution campaign via Google Ads. He receives an email with a screenshot showing a malicious sponsored result for Bing Webmaster Tools. He analyzes the HTML attributes and finds a suspicious domain (markov-chains.com). Visiting the site, he discovers injected JavaScript that leads to a phishing kit. The kit redirects to a fake Bing sign-in page, which prompts the user to download a ‘Microsoft security module’ (actually a batch file). The batch file downloads and executes PowerShell scripts, eventually delivering a backdoored version of TortoiseSVN. The malware uses DLL side-loading via a malicious crshhndl.dll to establish web socket-based command and control. John demonstrates the analysis process using tools like WebCrack, REMnux, and Any.Run, and identifies the malware as part of the ‘Web Kratos’ phishing kit. He concludes by warning viewers about the risks of clicking sponsored results and emphasizes the importance of ad blockers.

147 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world malvertising campaign, showing the entire attack chain from ad to payload. The argumentation is solid, based on hands-on analysis and clear reasoning. John explains each step, from inspecting HTML to reverse engineering the final DLL, making the technical details accessible. He also acknowledges uncertainties and encourages viewer input, which adds to the credibility.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates rigorous scientific methodology: John uses multiple tools (WebCrack, REMnux, Any.Run, .NET Peak) and verifies findings. He compares the malicious package with the legitimate TortoiseSVN to identify the tampered DLL. The sources cited are primarily the tools and resources listed in the description, which are relevant. The title accurately reflects the content, and the video is well-structured.

135 words

Title / Content Match

The title accurately reflects the content, as the video documents a real incident where Google served a malicious ad.

Quality & Reliability

8/10

The video provides a detailed walkthrough of a malware distribution campaign via Google Ads, with hands-on analysis and clear explanations. The author demonstrates technical expertise and uses appropriate tools, but the analysis is based on a single case and some steps are speculative.

Key Moments

Cited Sources

  • CodeCrafters — Resource for learning to code, mentioned in description
  • CyberDefenders — Blue team training and SOC analyst certifications
  • InfoSec Map — Cybersecurity events map
  • Newsletter — John Hammond's newsletter
  • OpenVPN — Host your own VPN
  • Just Hacking Training — Cybersecurity training
  • Vanta — Sponsor, compliance automation

Concurring Sources

  • Malwarebytes Labs on malvertising — General information on malvertising risks
  • CISA on phishing — Government guidance on phishing

Contribution & Novelties

This video provides a detailed, real-world case study of a malvertising campaign, showing the full attack chain from ad to payload. It highlights the risks of sponsored results and demonstrates practical malware analysis techniques. The discovery of the Web Kratos phishing kit and the DLL side-loading method adds to the understanding of current threat actor tactics.

Pour aller plus loin :

  • Malvertising — Overview of malvertising and its risks.
  • DLL hijacking — Explanation of DLL side-loading technique.
  • Phishing — General information on phishing attacks.
  • TortoiseSVN — Official site of the legitimate software that was backdoored.
  • Any.Run — Interactive malware sandbox used in the video.

104 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a strong technical level. The overall reliability is slightly lower due to the single-case nature and some speculative elements. The video is a valuable educational resource for cybersecurity enthusiasts.

Reliability 7/10

💬 The comments are overwhelmingly positive, with many viewers sharing similar experiences of encountering malicious ads on Google. The sentiment is supportive of the video's message and appreciative of the detailed analysis. Sur les 30 commentaires analysés, le climat est très positif, avec une majorité de retours d'expérience et de remerciements.