Phishing Campaign Uses Google Ads to Steal Ledger Recovery Phrases

· Original article ↗

Summary

Zscaler ThreatLabz analyzed a campaign that used fraudulent Google ads and rotating redirects to send Ledger users to a fake site that collected their secret recovery phrases.

Key points

  • ThreatLabz observed the campaign in August 2026, targeting Ledger users in the United States, Europe, and parts of Asia.
  • Fraudulent sponsored ads for Ledger-related searches appeared under a long-standing, verified advertiser account, which may have been compromised.
  • The redirect chain ran from Google Cloud Storage through changing Vercel domains to a Google Sites page embedding the phishing site.
  • Vercel redirect domains appeared to change every 15–20 minutes during analysis.
  • The fake Ledger interface offered device downloads and used a false verification flow to prompt users for their secret recovery phrases.
  • Submitted phrases were sent to an attacker-controlled Vercel endpoint; the page displayed an error after the first submission and collected the phrase again.
  • Zscaler identifies the activity as HTML.Phish.Ledger and lists Google Cloud Storage, Google Sites, and Vercel indicators.

Article Details

Attack Vectors
  • Fraudulent Google ads for Ledger-related searches directed users into a phishing redirect chain.
  • Google Cloud Storage URLs redirected visitors through changing Vercel-hosted domains to Google Sites pages that displayed phishing content in an iframe.
  • A page imitating Ledger used a fake device-verification process to solicit secret recovery phrases and send submissions to an attacker-controlled Vercel endpoint.
  • The phishing page collected device metadata and monitored user interactions, potentially to distinguish visitors from automated analysis tools.
Defensive Notes
  • Zscaler reports detecting indicators associated with the campaign under the threat name HTML.Phish.Ledger.
  • ThreatLabz observed Vercel redirect domains changing approximately every 15–20 minutes, making domain-reputation-based detection harder.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEnode-f1ey[.]vercel[.]appVercel hostname listed among attacker-used redirect and collection infrastructure.
HOSTNAMErouter-wdoi[.]vercel[.]appVercel hostname listed among attacker-used redirect and collection infrastructure.
HOSTNAMErpc-gbz5[.]vercel[.]appVercel hostname listed among attacker-used redirect and collection infrastructure.
HOSTNAMEsoyyoo-cwpc5n0e[.]vercel[.]appVercel hostname listed among attacker-used redirect and collection infrastructure.
HOSTNAMEwhyavc-qwmv6stx[.]vercel[.]appVercel hostname listed among attacker-used redirect and collection infrastructure.

MITRE ATT&CK

Vendors

Products

Countries

Industries

Related Articles