{"id":45406,"date":"2026-04-15T02:13:34","date_gmt":"2026-04-14T18:13:34","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/ai-driven-pushpaganda-scam-exploits-google-discover-to-spread-scareware-and-ad-fraud\/"},"modified":"2026-04-15T02:13:34","modified_gmt":"2026-04-14T18:13:34","slug":"ai-driven-pushpaganda-scam-exploits-google-discover-to-spread-scareware-and-ad-fraud","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/15\/ai-driven-pushpaganda-scam-exploits-google-discover-to-spread-scareware-and-ad-fraud\/","title":{"rendered":"AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud"},"content":{"rendered":"<div style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiON8Ew8R1EO7t3yoLoTFdM2hQsDW9AtBPPBcNuPup6ZmpGta3VyYlkhiqqRlW5CDWpnU_3IJ-EAbnV6nrfzJ4V3mdWIng75afS2TPvZOs-_MLc0a5lxiLwR5H-EWmi1C0ctYCBZSBNbF9CCGcdm7BrNaWunTp8QvBkmqJwq0Yvde9bQxbhooyIYaXRiebP\/s1600\/ad-fraud.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiON8Ew8R1EO7t3yoLoTFdM2hQsDW9AtBPPBcNuPup6ZmpGta3VyYlkhiqqRlW5CDWpnU_3IJ-EAbnV6nrfzJ4V3mdWIng75afS2TPvZOs-_MLc0a5lxiLwR5H-EWmi1C0ctYCBZSBNbF9CCGcdm7BrNaWunTp8QvBkmqJwq0Yvde9bQxbhooyIYaXRiebP\/s1600\/ad-fraud.jpg\" alt=\"AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud\"\/><\/a><\/div>\n<p>Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into&nbsp;Google&#8217;s <a href=\"https:\/\/search.google\/intl\/en-GB\/ways-to-search\/discover\/\">Discover&nbsp;feed<\/a> and trick users into enabling persistent browser notifications that lead to scareware and financial&nbsp;scams.<\/p>\n<p>The campaign, which has been found to target the personalized content feeds of Android and Chrome users, has been&nbsp;codenamed <strong>Pushpaganda<\/strong> by HUMAN&#8217;s Satori Threat Intelligence and Research&nbsp;Team.<\/p>\n<p>&#8220;This operation, named for push notifications central to the scheme, generates invalid organic traffic from real mobile devices by tricking users into subscribing to enabling notifications that presented alarming messages,&#8221; researchers Louisa Abel, Vikas Parthasarathy, Jo\u00e3o Santos, and Adam&nbsp;Sell <a href=\"https:\/\/www.humansecurity.com\/learn\/resource\/satori-threat-intelligence-alert-pushpaganda-manipulates-google-discovery-feeds-with-ai-generated-content-to-spread-malicious-notifications\/\">said<\/a> in a report shared with The Hacker&nbsp;News.<\/p>\n<p>At its peak, about 240 million bid requests have been associated with 113 domains linked to the campaign&nbsp;over a seven-day&nbsp;period. The&nbsp;threat, although observed targeting India, has since expanded to other regions like the U.S., Australia, Canada, South Africa, and the&nbsp;U.K.<\/p>\n<p>The findings demonstrate how threat actors abuse AI to hijack trusted discovery surfaces and turn them into delivery vehicles for scareware, deepfakes, and financial fraud, Gavin Reid, chief information security officer at HUMAN, said. Google&nbsp;has since rolled out a fix to address the spam&nbsp;issue.<\/p>\n<p>The entire scheme hinges on the scammers luring unsuspecting users through Google Discover to trick them into visiting misleading news stories filled with AI-generated content. Once&nbsp;a user lands on one of the actor-controlled domains, they are coerced into enabling push notifications that deliver fake legal threats and&nbsp;scams.<\/p>\n<p>Specifically, the scareware notifications, once clicked, redirect users to additional sites operated by the threat actors, generating organic traffic to ads embedded in those sites and enabling them to generate illicit&nbsp;revenue.<\/p>\n<div style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5Wn2kkMjtbnw1-KkAsjvAMfATolufczv33o1P7UttJOTKOAc6YScPd3Tvt6sCVzs6yXF0V4xIvHMM0EHuC6Q4RNnW0Lsmq_xlTti9tv53wvZRIzRireicc3KQC-zalXpW1vjWn6Mtwd8Sdy16pPaCIB6kMLIqIMyihLwqSETUljDIF2vSUKwS2478O6Dh\/s1600\/flow.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" border=\"0\" data-original-height=\"928\" data-original-width=\"1921\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5Wn2kkMjtbnw1-KkAsjvAMfATolufczv33o1P7UttJOTKOAc6YScPd3Tvt6sCVzs6yXF0V4xIvHMM0EHuC6Q4RNnW0Lsmq_xlTti9tv53wvZRIzRireicc3KQC-zalXpW1vjWn6Mtwd8Sdy16pPaCIB6kMLIqIMyihLwqSETUljDIF2vSUKwS2478O6Dh\/s1600\/flow.jpg\" alt=\"AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud\"\/><\/a><\/div>\n<p>This is not the first time threat actors have weaponized push notifications to redirect to sketchy websites. In&nbsp;September 2025, Infoblox shed light on a threat actor known&nbsp;as <a href=\"https:\/\/thehackernews.com\/2025\/09\/vane-viper-generates-1-trillion-dns.html\">Vane&nbsp;Viper<\/a> that has engaged in systematic push notification abuse to serve ads and facilitate ClickFix-style social engineering campaigns.<\/p>\n<p>&#8220;Malware-based threats involving push notifications, both for web and mobile platforms, aren&#8217;t a novel threat, especially when you consider the way in which they create a sense or urgency,&#8221; Lindsay Kaye, vice president of threat intelligence at HUMAN Security, told The Hacker News. &#8220;In many cases, users are quick to click, either to make them go away or to get more information, making them an effective tool in a malware author&#8217;s&#160;arsenal.&#8221;<\/p>\n<p>The disclosure also comes a little over a month after HUMAN identified a collection of more than 3,000 domains and 63 Android apps that it said constituted one of the largest ad fraud laundering marketplaces ever uncovered. Dubbed&nbsp;Low5 for its use of HTML5-based game and news sites, the operation has been found to monetize the domains&nbsp;as cashout sites for sophisticated fraud schemes,&nbsp;including <a href=\"https:\/\/thehackernews.com\/2025\/03\/badbox-20-botnet-infects-1-million.html\">BADBOX&nbsp;2.0<\/a>.<\/p>\n<p>&#8220;The operation peaked at roughly 2 billion bid requests a day and may have operated on as many as 40 million devices worldwide,&#8221; the&nbsp;company <a href=\"https:\/\/www.humansecurity.com\/learn\/blog\/satori-threat-intelligence-alert-low5-apps-and-domains-launder-multiple-ad-fraud-schemes\/\">said<\/a>. &#8220;Apps associated with Low5 include code that instructs user devices to visit one of the domains connected with the scheme and click on ads found&nbsp;there.&#8221;<\/p>\n<p>Cashout sites, also called ghost sites, are used to conduct content-driven fraud, where the attackers use bogus sites and apps to sell space to advertisers who may assume their ads will be viewed by humans. The&nbsp;Android apps in question have been removed from the Google Play&nbsp;Store.<\/p>\n<p>&#8220;A shared monetization layer spanning more than 3,000 domains allows multiple threat actors to plug into the same infrastructure, creating a distributed laundering system that increases threat resilience, complicates attribution, and enables rapid replication,&#8221; HUMAN&nbsp;added.<\/p>\n<p>&#8220;A key takeaway from this research is that monetization infrastructure can survive even after a specific fraud campaign is shut down. If&nbsp;one malicious app or device network is removed, the same cashout domains can still be reused by other actors. Low5&nbsp;reinforces the need for continuous, aggressive threat intelligence and detection expertise to hunt down cashout domains and flag them&nbsp;pre-bid.&#8221;<\/p>\n<div><\/div>\n<div>Found this article interesting?  Follow us on <a href='https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ' rel='noopener' target='_blank'>Google News<\/a>, <a href='https:\/\/twitter.com\/thehackersnews' rel='noopener' target='_blank'>Twitter<\/a> and <a href='https:\/\/www.linkedin.com\/company\/thehackernews\/' rel='noopener' target='_blank'>LinkedIn<\/a> to read more exclusive content we post.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into&nbsp;Google&#8217;s Discover&nbsp;feed and trick users into enabling persistent browser notifications that lead to scareware and financial&nbsp;scams.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-45406","post","type-post","status-publish","format-standard","hentry","category-thehackernews"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45406"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45406\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}