Threat actors used fraudulent, Google-verified sponsored advertisements impersonating Ledger to target hardware-wallet users in the United States, Europe, and parts of Asia. Victims were routed through a multi-stage chain involving Google Cloud Storage, rapidly rotating Vercel redirect domains, and Google Sites pages that embedded a counterfeit Ledger site in an iframe; the Vercel infrastructure rotated approximately every 15–20 minutes to frustrate reputation-based blocking.
The fake site fingerprinted visitors and mimicked Ledger software-download, device-setup, and firmware-verification workflows before requesting the victim's secret recovery phrase. It used the BIP-39 English wordlist to provide phrase autocomplete and collected device and behavioral metadata; submitted phrases were exfiltrated, including to attacker-controlled Vercel endpoints, enabling operators to restore victims' wallets and transfer funds without access to the physical Ledger devices.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
In August 2026, Zscaler ThreatLabz analyzed a campaign that used malicious sponsored Google ads impersonating Ledger to target cryptocurrency users in the United States, Europe, and parts of Asia. The ads routed victims through Google Cloud Storage, rotating Vercel redirects, and Google Sites-hosted iframe content to harvest Ledger secret recovery phrases.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.