Categories: CyberHoot

Malvertising Alert: Phishing Campaign Targets Onfido Users via Google Ads

Sponsored
class="elementor-section elementor-top-section elementor-element elementor-element-4a1fddc7 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="4a1fddc7" data-element_type="section">
In April 2025, cybersecurity firm Push Security uncovered a sophisticated malvertising campaign targeting Onfido uses. Onfido, is a digital identity verification platform widely used in fintech, HR, and other regulated industries. This campaign leveraged Google Ads and the Evilginx phishing tool. Evilginx is a publicly available phishing solution used to deceive users into revealing sensitive credentials through phishing attacks.

The Attack Unveiled

The attackers purchased Google Ads that appeared above legitimate Onfido search results. These ads directed users to a counterfeit login page hosted on a deceptive domain: dashboard.onfido.us.com. While resembling a legitimate U.S. government domain, .us.com is a commercial domain, making it easier for malicious actors to exploit.

Once users clicked the ad, they were taken to a cloned Onfido login page. This page was generated using Evilginx, a man-in-the-middle phishing tool that proxies legitimate login pages to capture session tokens and credentials. Notably, the phishing page was configured to display correctly only when accessed via the malicious Google Ad. Direct visits to the domain resulted in a redirection to a 404 page on the legitimate Onfido site, a tactic designed to evade detection by security scanners.

Implications and Risks

This malvertisement phishing campaign demonstrates the increasing sophistication  being used in phishing attacks.  Specifically, hackers are seeking:  

  • Diversification of Targets: Attackers are moving beyond traditional targets like Microsoft and Google, focusing on platforms like Onfido that manage sensitive authentication data.  Similar targets can be expected for competitors such as ID Now, or Ping Identity.
  • Bypassing Traditional Defenses: By exploiting Google Ads, attackers circumvent email-based security measures, reaching users through trusted channels.
  • Advanced Evasion Techniques: The use of Evilginx and conditional page rendering demonstrates a high level of sophistication aimed at avoiding detection.

Protective Measures

To mitigate such threats:

Sponsored
  • Educate and Test Employees: Regular training and implementing positive phishing simulations that help staff recognize and avoid phishing attacks. Alert them to emerging risks tied to web browsing search results and sponsored advertisements.
  • Cautious Browsing: Be wary of sponsored links in search results. Prioritize direct navigation to known websites.
  • Verify URLs: Ensure the domain matches the official website before entering credentials.
  • Implement Multi-Factor Authentication (MFA): MFA adds an additional layer of security, making unauthorized access more difficult.

As cyber threats evolve, staying informed is very important. Organizations must proactively adopt early warning strategies to alert staff to emerging security threats.  Subscribe to CyberHoot’s newsletters here to stay ahead of these threats.

Secure your business with CyberHoot Today!!!

rssfeeds-admin

Share
Published by
rssfeeds-admin

Recent Posts

The Pitt Season 2, Episode 10: “4:00 PM” Review

Warning: This review contains full spoilers for The Pitt Season 2, Episode 10!The best episodes…

14 minutes ago

The Total Wireless by Verizon “Apple iPhone 17e On Us” Deal Explained (New Release)

Apple recently released its newest budget smartphone - the Apple iPhone 17e - on March…

2 hours ago

Blight: Survival Remerges After 1.5 Million Steam Wishlists and a Viral Trailer With a New Look at Gameplay

Blight: Survival has reemerged with a new gameplay trailer — and its developers are promising…

2 hours ago

The Bluetti AC70 768Wh 1,000W LiFePO4 Power Station Is 20% Cheaper on AliExpress Than on Amazon

Bluetti is well known for its high quality yet affordable power stations and solar generators.…

3 hours ago

Stupid Never Dies Preview: An Outrageous Action RPG with Heart (Even if that Heart Isn’t Beating)

There’s something endlessly endearing about a good-natured dummy. Just a happy, optimistic doofus that can…

3 hours ago

WATCH LIVE: Sweetwater Rattlesnake Roundup Parade

(KTAB/KRBC) - The Sweetwater Rattlesnake Roundup Parade for 2026 is taking place at 4:30 p.m.,…

4 hours ago

This website uses cookies.