Scam Alert: Beware of Google scam ads promoting fake installers for popular programs

ESET, an Eastern European cybersecurity software company, has found a malware campaign that had been targeting Chinese-speaking people in Malaysia, along with other countries in Southeast Asia and East Asia. It seems as though these scammers had been running Google Ads targeting people who search up for popular applications, pushing for their ad spots to appear on top of legitimate search results and getting users to click on their fake website.

Specifically, they’ve been creating fake websites that look identical to the websites of popular programs and softwares, such as Google Chrome, WhatsApp, Signal, Skype, Telegram and more. People who search these up and click on their Google Ad rather than the actual website will then be greeted by a look-a-like website that offers a download to the program that they had been looking for. However, when they download the installer, what they’ll get instead is a Trojanised installer containing the virus FatalRAT.

FatalRAT is a remote access Trojan that would grant the hacker access and control to the victim’s computer. It gives the hacker a bunch of functionalities to perform malicious tasks, such as capture your keystrokes, steal or even delete data stored on your computer, as well as download and execute files. ESET found that the malware campaign had been going on between August 2022 till January 2023, but curiously these Trojanised installers have been seen in the wild since at least May 2022.

Incidentally, all of these fake websites ended up pointing to he same IP address, a server hosting the Trojanised software. These websites seemingly targeted Chinese-speaking users in particular, by claiming to offer Chinese-language versions of software that isn’t available in China. ESET has since reported these scam ads to Google, who then removed them.

As a general rule of thumb, you should always pay attention to the address bar in your browser to ensure that you’re at a legitimate website rather than a fake one. Furthermore, when you download files, always double check that you’re getting the files you intended to download. If you do find out that you’ve been scammed, you can dial 997 to contact the National Scam Response Center, which was set up last October to coordinate a rapid response specifically for online financial scams.

Recent Posts

Cinematic Muscle, Mid-Range Price: Why the Xiaomi TV S Pro Mini LED 75” (2026) is the Year’s Biggest TV Disruptor

This post is brought to you by Xiaomi. Finding a large 4K TV with advanced…

15 hours ago

Kelle Energy and EVC to rollout 100 Mobile EV Chargers in Malaysia

Kelle Energy, a Singapore-based clean energy technology company, today officially launched their Mobile EV Chargers…

18 hours ago

Proton e.MAS 7 PHEV is now official: Available from as low as RM105,800

Pro-Net has officially launched the new Proton e.MAS 7 PHEV, which is the first plug-in…

21 hours ago

Zeekr 9X coming to Malaysia: 1,381hp luxury 6-seat PHEV, expected to be priced above RM500K

Zeekr will soon introduce its new flagship SUV, the Zeekr 9X, in Malaysia. Measuring over…

2 days ago

Record high 3,276 Proton e.MAS EVs delivered in January 2026

Pro-Net is starting 2026 with a bang, delivering a record-high 3,276 EVs in January 2026.…

3 days ago

Gentari Go discontinues Power Pass subscription plans

This is your last call to pick up a Gentari Go Power Pass membership plan…

5 days ago

This website uses cookies.