메뉴
BL
Ars Technica • 13시간 전

구글 광고를 통해 유포된 화면 잠금 기술 지원 사기 주의보

IMP
6/10
핵심 요약

보안업체 Netskope는 구글 광고를 통해 Windows와 Mac 기기의 화면을 멈추게 하고 가짜 콜센터 전화를 유도하는 정교한 기술 지원 사기 캠페인을 발견했습니다. 악성 광고는 지도, 날씨, 부동산, 스포츠 등 유명 사이트에 게재되었으며, 619개 고객 조직의 사용자가 클릭했지만 모두 차단되었습니다. 사기 키트는 암호화와 기기별 맞춤 경고 화면으로 탐지를 우회하며, 실제로는 기기가 잠기지 않아 브라우저를 닫으면 대부분 해결됩니다.

번역된 본문

연구자들은 최근 Windows와 Mac 기기의 화면을 멈추게 하고 가짜 콜센터에 즉시 전화하라는 메시지를 표시하는 정교한 기술 지원 사기를 유포하는 구글 광고를 발견했다고 밝혔다. 해당 광고는 방문자가 많은 지도, 날씨, 부동산, 문서 호스팅, 스포츠 사이트 등 웹 전역에 게재되었다. 표시된 번호로 전화한 사용자들은 고액의 비용을 지불하거나, 기기에 대한 원격 접근 권한을 부여하거나, 개인정보를 넘기도록 강요받았다.

8월 31일부터 9월 14일까지 보안업체 Netskope는 619개 고객 조직의 사용자들이 이 악성 광고를 클릭하는 것을 관찰했으나, Netskope가 콘텐츠를 차단했기 때문에 실제로 사기를 당한 사람은 없었다. 조직의 약 62%는 미국에 기반을 두고 있으며, 일본과 호주가 각각 2위와 3위를 차지했다. 이 회사는 인터넷 활동의 아주 일부만 볼 수 있기 때문에, 이 광고에 노출된 사람들(피해자 포함)의 수는 훨씬 많을 것으로 보인다. Netskope는 최소 284개의 합법적인 퍼블리셔 사이트에서 250개 이상의 구글 광고 캠페인 ID를 추적했다.

그렇다면 '루이 아저씨'는 어떻게 됐을까? Netskope는 "피해자 입장에서는 이러한 기법이 평범한 광고 클릭을 가짜 보안 경고로 멈춰버린 것처럼 보이는 브라우저로 바꿔버린다"고 말했다. "잠금 화면은 화면을 가득 채우고, 커서를 숨기고, 일반적인 종료 키를 무시하며, 브라우저를 지연시켜 고장 난 컴퓨터처럼 느끼게 만들어 화면의 번호로 전화하게 압박한다. 컴퓨터의 어떤 것도 실제로 잠긴 것은 아니지만, 그 순간에는 사람들이 사기에 넘어갈 만큼 설득력이 있다."

이제 와서는 이 사이트 독자들 상당수를 포함한 많은 사람들이 이런 사기에 넘어가는 사람들을 비웃고 비난한다. 하지만 이러한 비판은 컴퓨터와 인터넷의 작동 원리를 거의 이해하지 못하는 상당수 인터넷 사용자들을 간과하고 있다. 일을 빨리 처리해야 한다는 필요성과 웹 탐색이 점점 어려워지는 상황이 이러한 인지 부족과 결합하면서, 상당수 사용자가 완벽한 표적이 되고 있다. 일부 비판자들에게도 경계할 만큼 알지 못하는 가까운 친구와 가족이 있을 것임은 의심의 여지가 없다.

사기를 더욱 그럴듯하게 만드는 것은, 가짜 경고를 표시하는 소프트웨어 키트가 은밀하게 작동하도록 설계되어 실제 감염의 징후를 매우 유사하게 모방한다는 점이다. 브라우저 주소창이 사라지고, 경고 화면이 화면 전체를 차지하며, ESC 키와 다른 많은 키 입력이 비활성화된다. 브라우저 성능이 저하되고, 소리가 재생되며, 페이지가 느려지면서 심각한 문제가 발생한 것 같은 인상을 준다. 기기를 재시작하지 말고 즉시 콜센터로 전화하라는 메시지가 깜빡인다. 브라우저를 닫으려 해도 사기 메시지가 다시 새로고침될 뿐이다.

경고는 사용자가 마우스를 움직인 후에만 나타난다. 이 소프트웨어는 암호화되어 있으며, 복호화된 후에만 브라우저 메모리에 표시된다. 이 두 가지 조건 때문에 많은 엔드포인트 보안 소프트웨어와 어쩌면 구글의 광고 필터도 악성코드를 탐지하지 못한다. 또한 경고 광고는 대상 사용자 기기가 Windows인지 macOS인지에 따라 다르게 표시된다.

구글은 자사 스캐너가 이 사기 캠페인을 놓친 원인에 대해 언급하지 않았고, 방대한 광고 플랫폼에서 이 광고들이 완전히 제거되었다는 어떤 징후도 보여주지 않았다. 구글은 성명에서 "우리는 사기에 대해 용인하지 않는다. 이 보고서의 캠페인을 적극적으로 조사하고 있으며, 정책을 위반하는 계정에 대해 조치를 취할 것"이라고 밝혔다. 이 회사는 작년에 게재되기 전에 위반 광고의 99% 이상을 차단했다고 밝힌 바 있다.

Netskope가 지적했듯이, 사기 창을 닫는 일반적인 키 대부분이 비활성화되어 있지만 기기가 실제로 잠긴 것은 아니다. 이 경우와 유사한 많은 사례에서 사용자는 여전히 창을 쉽게 닫을 수 있다. Windows와 macOS 모두...

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Researchers say they recently found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices and displays messages urgently instructing them to phone a bogus call center. The ads were displayed all over the web, including on high-traffic maps, weather, real-estate, document-hosting, and sports sites. Users who called the number were then urged to pay hefty fees, grant remote access to their devices, or divulge personal information. From August 31 to September 14, security firm Netskope observed users from 619 customer organizations click on the malicious ads, although none of them were actually scammed because Netskope blocked the content. Roughly 62 percent of the organizations were based in the US, with Japan and Australia accounting for the Nos. 2 and 3 spots. Since the firm has visibility into only a tiny sliver of Internet activity, the number of people exposed to the ads—including those who fell victim to it—is likely much higher. Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. So, what about Uncle Louie? “For the victim, that tradecraft turns an ordinary ad click into a browser that appears to seize up on a fake security warning,” Netskope said . “The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen. Nothing on the computer is actually locked, but in the moment it is convincing enough to push people toward the scam.” By now, many people, including a fair number of readers of this site, ridicule and shame people who fall for such scams. These criticisms fail to account for a sizable portion of Internet users who have little or no understanding of how computers and the Internet work. Combined with their need to get things done quickly and the growing difficulty of navigating the web, this lack of awareness makes a sizable portion of users prime targets. There’s little doubt that some critics have close friends and family who are among those who simply don’t know enough to be wary. Further making the scam convincing, the software kit that delivers the fake warnings is designed to be stealthy and closely mimic the signs of a real infection. The browser address bar no longer appears, the warning screen occupies the entire screen, and presses of escape and many other keys are disabled. The browser performance degrades, sounds play, and pages lag, giving the impression that something is seriously wrong. Messages urging the user not to restart the machine and to call a call center immediately flash. Attempts to close the browser only make the scam message refresh. The warnings appear only after a user makes a mouse movement. The software is also encrypted and only decrypted and then displayed in the browser memory. Both these conditions prevent many endpoint security wares—and possibly Google’s ad filters—from detecting the malice. Further, the warning ads appear differently depending on whether the targeted user device is running Windows or macOS. Google didn’t say what caused its scanners to miss the scam campaign or give any indication the ads have been fully removed from its massive ad platform. “We have zero tolerance for scams,” the company said in a statement. “We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.” The company has said that last year it blocked over 99 percent of violating ads before they were ever served. As Netskope noted, devices aren’t actually locked up, even though most of the usual keys for closing the scam window have been disabled. In this case and many similar ones, users can still easily exit the window. For both Windows and macOS devices, this can be done in most cases by pressing the escape key and holding it for several seconds. The press will force the browser out of full screen and release the keyboard lock, and from there, the tab can be closed. An alternative approach is to invoke the Windows Task Manager (control-shift-escape) and exit the browser. On a Mac, the keys are (cmd-option-escape). In both cases, users can reopen the browser without restoring the previous session. No legitimate company will ever advise users to call a phone number when they’re infected. Under no case should people hit by tech support scams call the number. Those who provide informal tech support for friends and family might consider writing the above advice on a Post-it and affixing it to screens. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 84 Comments