Malicious Google search advertisements were used to impersonate legitimate software and brand websites, steering users to spoofed download pages that delivered IcedID malware. In one documented chain, a search for AnyDesk led through Google ad infrastructure and a traffic distribution system to a fake site, wwwanydesk[.]top, which served a ZIP archive from Google Firebase Storage containing an MSI installer. The installer abused rundll32.exe to launch a malicious DLL export named init, installing IcedID through modified legitimate DLLs such as sqlite3.dll, tcl86.dll, libcurl.dll, and ConEmuTh.x64.dll to evade detection.
Researchers and U.S. law enforcement said the campaign relied on pay-per-click malvertising, cloned websites, and lookalike domains that appeared prominently in search results with little visual distinction from legitimate links. After infection, compromised hosts contacted multiple IcedID command-and-control servers and in some cases pulled follow-on payloads tied to Cobalt Strike, Sliver, and DonutLoader, underscoring the risk of data theft and ransomware. The FBI warned that the same ad-abuse tactic is also being used to steal credentials and cryptocurrency funds, and urged users to verify URLs, avoid downloading software through ads, and report incidents to IC3.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2022-12-21, the FBI warned that cybercriminals were abusing search engine advertisement services to impersonate legitimate brands and direct users to spoofed sites. The advisory said the sites could deliver malware, including ransomware, or steal credentials and financial information.
After infection, the host communicated with multiple IcedID command-and-control servers and generated additional traffic including VNC backchannel activity. The infection chain also fetched follow-on payloads associated with Cobalt Strike and Sliver and/or DonutLoader, illustrating post-compromise escalation.
On 2022-12-14, a Google search for AnyDesk led through Google ad infrastructure and a traffic distribution system to a fake AnyDesk page at wwwanydesk[.]top that offered a malicious download. The activity was part of a broader December 2022 IcedID malvertising campaign abusing Google pay-per-click ads and cloned brand websites.
The downloaded ZIP archive contained an MSI installer that dropped a DLL and executed it with rundll32.exe using the export name "init" to install IcedID. Trend Micro described this MSI-delivered loader as an atypical December 2022 IcedID technique built from modified legitimate DLLs to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceic3.gov
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.