Phishing Campaign Uses Google Ads to Steal Ledger Recovery Phrases

Summary
Zscaler ThreatLabz analyzed a campaign that used fraudulent Google ads and rotating redirects to send Ledger users to a fake site that collected their secret recovery phrases.
Key points
- ThreatLabz observed the campaign in August 2026, targeting Ledger users in the United States, Europe, and parts of Asia.
- Fraudulent sponsored ads for Ledger-related searches appeared under a long-standing, verified advertiser account, which may have been compromised.
- The redirect chain ran from Google Cloud Storage through changing Vercel domains to a Google Sites page embedding the phishing site.
- Vercel redirect domains appeared to change every 15–20 minutes during analysis.
- The fake Ledger interface offered device downloads and used a false verification flow to prompt users for their secret recovery phrases.
- Submitted phrases were sent to an attacker-controlled Vercel endpoint; the page displayed an error after the first submission and collected the phrase again.
- Zscaler identifies the activity as HTML.Phish.Ledger and lists Google Cloud Storage, Google Sites, and Vercel indicators.
Article Details
- Attack Vectors
- Fraudulent Google ads for Ledger-related searches directed users into a phishing redirect chain.
- Google Cloud Storage URLs redirected visitors through changing Vercel-hosted domains to Google Sites pages that displayed phishing content in an iframe.
- A page imitating Ledger used a fake device-verification process to solicit secret recovery phrases and send submissions to an attacker-controlled Vercel endpoint.
- The phishing page collected device metadata and monitored user interactions, potentially to distinguish visitors from automated analysis tools.
- Defensive Notes
- Zscaler reports detecting indicators associated with the campaign under the threat name HTML.Phish.Ledger.
- ThreatLabz observed Vercel redirect domains changing approximately every 15–20 minutes, making domain-reputation-based detection harder.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | node-f1ey[.]vercel[.]app | Vercel hostname listed among attacker-used redirect and collection infrastructure. |
| HOSTNAME | router-wdoi[.]vercel[.]app | Vercel hostname listed among attacker-used redirect and collection infrastructure. |
| HOSTNAME | rpc-gbz5[.]vercel[.]app | Vercel hostname listed among attacker-used redirect and collection infrastructure. |
| HOSTNAME | soyyoo-cwpc5n0e[.]vercel[.]app | Vercel hostname listed among attacker-used redirect and collection infrastructure. |
| HOSTNAME | whyavc-qwmv6stx[.]vercel[.]app | Vercel hostname listed among attacker-used redirect and collection infrastructure. |
MITRE ATT&CK
T1071.001 · Web ProtocolsThe phishing flow used web redirects across Google Cloud Storage, Vercel, and Google Sites; the page sent submitted phrases to a Vercel-hosted endpoint.T1204.001 · Malicious LinkUsers clicking a malicious sponsored ad entered the redirect chain leading to the phishing page.T1566.002 · Spearphishing LinkFraudulent Google ads led Ledger users to a phishing page that requested their secret recovery phrases.T1583.001 · DomainsThe campaign used changing Vercel-hosted domains for redirects and phishing delivery.
Vendors
GoogleThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases.LedgerThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases.VercelThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases.ZscalerZscaler detects this activity as HTML.Phish.Ledger.
Products
Google AdsThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases.Google Cloud StorageThe campaign sent victims through Google Cloud Storage and Google Sites, then used a fake device-verification flow to collect wallet credentials.Google SitesThe campaign sent victims through Google Cloud Storage and Google Sites, then used a fake device-verification flow to collect wallet credentials.Ledger hardware walletsVercelThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases.