Researchers said a threat operation dubbed Pushpaganda manipulated Google Discover on Android and Chrome to lure users into enabling malicious browser push notifications. The campaign relied on 113 actor-controlled domains publishing AI-generated, sensational news pages that mimicked legitimate content and used social-engineering themes including fake government deposits, tax notices, arrest warrants, missed calls, and bank alerts. HUMAN’s Satori Threat Intelligence and Research Team reported the activity first focused on India before expanding to Australia, the United States, and other regions.
Once users landed on the pages, deceptive prompts and buttons pushed them to subscribe to notifications, while JavaScript-based tab rotation opened additional domains to inflate traffic and advertising revenue. At its peak, the operation generated roughly 240 million bid requests in seven days, indicating a large-scale ad fraud component alongside the notification abuse. Researchers shared the infrastructure with Google, which said it deployed a fix to prevent this type of manipulative low-quality content from appearing in Discover feeds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Google said it deployed a fix to prevent this type of manipulative low-quality content from appearing in Discovery feeds. The action was taken in response to the campaign's abuse of Google Discover to drive malicious notification subscriptions and ad fraud.
HUMAN researchers shared the malicious domains associated with Pushpaganda with Google after identifying the campaign's abuse of Google Discover and browser notification prompts. This disclosure supported mitigation of the manipulation technique.
At its peak, the operation generated about 240 million bid requests in a seven-day period while using deceptive buttons and JavaScript-based tab rotation to open extra domains, inflate traffic, and produce fraudulent advertising revenue. Researchers linked the activity to 113 actor-controlled domains.
After initially targeting India, the Pushpaganda operation broadened its activity to Australia, the United States, and additional countries. The campaign used social-engineering lures such as fake government deposits, tax notices, arrest warrants, missed calls, and bank alerts.
HUMAN's Satori Threat Intelligence and Research Team identified a threat operation dubbed Pushpaganda that used actor-controlled domains and AI-generated sensational news pages in Google Discover to trick users into enabling malicious browser push notifications. The campaign initially focused on users in India before later expanding to other regions.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehumansecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.