Malicious Ads Targeting Advertisers in the DNS Spotlight | WhoisXML API

Malicious Ads Targeting Advertisers in the DNS Spotlight

Google and Microsoft are consistently among the most-phished brands. Case in point: Microsoft topped a recently published list1, while Google ranked third.

A total of 97 domains were recently identified as indicators of compromise (IoCs) related to a new attack that targeted Microsoft advertisers. The threat actors used malicious Google ads to steal the login information of users of Microsoft’s advertising platform.2

WhoisXML API dove deep into the threat aided by our comprehensive DNS intelligence and unearthed connected artifacts comprising:

  • 204 email-connected domains
  • 25 IP addresses, 16 of which turned out to be malicious
  • 483 IP-connected domains
  • 417 string-connected domains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.zdnet.com/article/the-top-10-brands-exploited-in-phishing-attacks-and-how-to-protect-yourself/
  • [2] https://www.malwarebytes.com/blog/news/2025/01/microsoft-advertisers-phished-via-malicious-google-ads
Try our WhoisXML API for free
Get started