{"id":206034,"date":"2022-11-02T11:34:26","date_gmt":"2022-11-02T10:34:26","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=206034"},"modified":"2025-07-01T20:21:43","modified_gmt":"2025-07-02T03:21:43","slug":"malvertising-attacks-hiding-in-google-ads-gimp","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/malvertising-attacks-hiding-in-google-ads-gimp\/","title":{"rendered":"More malvertising attacks hiding in Google ads for GIMP image editing software"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We\u2019ve covered a series of innovative cyber attack methods recently, from hiding malware in fake job offers to \u2018malvertisers\u2019 pushing fake ads across advertising networks in a bid to trap unsuspecting victims and infect their devices with malware. Unfortunately, today we bring you news of <strong>a particular malvertising scam, that has been able to break into the Google ads network<\/strong> and is pushing malware in fake ads for the Photoshop alternative program GIMP.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"GIMP\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/4d35b5cc-96d1-11e6-978a-00163ec9f5fa\/994269698\/the-gimp-download%20(2).png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">GIMP<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/the-gimp.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/the-gimp.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-ad-for-gimporg-served-info-stealing-malware-via-lookalike-site\/\" target=\"_blank\" rel=\"noreferrer noopener\">a report<\/a> on BleepingComputer, which cites a <a href=\"https:\/\/www.reddit.com\/r\/GIMP\/comments\/ygbr4o\/comment\/iu85cgz\/\" target=\"_blank\" rel=\"noreferrer noopener\">Reddit post<\/a> by ZachIngram04, up until just last week, <strong>Googling the popular and free photo editing tool GIMP<\/strong>, widely seen as a reputable open-source alternative to Adobe Photoshop, would <strong>serve up fake ads that would take you to a fake version of the GIMP homepage<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the victims land on the fake homepage, they are <strong>shown a fake Download button <\/strong>that will install malware onto their computers and cause a wide variety of security issues and problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What is interesting to note is the innovative ways the scammers have been able to bypass the security features of the Google ad network, which included <strong>bulking out the malware file to 700 MB in size <\/strong>so that it more closely resembles the true size of the real file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main problem here is that the scammers have been able to <strong>serve up a malicious site that very naturally points you to a malicious download<\/strong> in one of the most common internet settings, the results of a Google search. Here, you are highly likely to just thoughtlessly go through the motions and download the file, but <strong>there are key aspects to look out for that could give away the dangerous nature of the site<\/strong> you are on and the file you are about to download.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, <strong>the actual URL of the fake site is gilimp.org<\/strong>, which is different to the real address, which is gimp.org. It even sounds strange when you read it, which is a real red flag. <strong>The other red flag in this instance is the download domain gimp.monster<\/strong>. Again, this domain is fake with the giveaway being that it goes to a .monster domain instead of a .org domain. Often scammers will try to trick users by serving up a fake root domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To learn more about these two detection methods as well as a wide variety of other red flags to look out for, check out our <a href=\"https:\/\/www.reddit.com\/r\/GIMP\/comments\/ygbr4o\/comment\/iu85cgz\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing scam detection infographic<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Image via: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-ad-for-gimporg-served-info-stealing-malware-via-lookalike-site\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve covered a series of innovative cyber attack methods recently, from hiding malware in fake job offers to \u2018malvertisers\u2019 pushing fake ads across advertising networks in a bid to trap unsuspecting victims and infect their devices with malware. Unfortunately, today we bring you news of a particular malvertising scam, that has been able to break &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/malvertising-attacks-hiding-in-google-ads-gimp\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;More malvertising attacks hiding in Google ads for GIMP image editing software&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":206045,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[2997],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-206034","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionthe-gimp"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/206034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=206034"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/206034\/revisions"}],"predecessor-version":[{"id":322961,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/206034\/revisions\/322961"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/206045"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=206034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=206034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=206034"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=206034"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=206034"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=206034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}