Zscaler Blog
Get the latest Zscaler blog updates in your inbox
Threat Actors Use Google Ads To Target Ledger Users
Introduction
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices.
In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases.
Key Takeaways
- In August 2026, ThreatLabz discovered a campaign in which fraudulent Google ads targeting Ledger users appeared under a Google-verified advertiser profile.
- The ads routed users through Google Cloud Storage and Vercel to a Google Sites page that displayed the phishing content in an iframe.
- The Google Cloud Storage page redirected users to Vercel domains that appeared to change every 15-20 minutes during the observation period.
- A fake device-verification process asked users for their secret recovery phrases and then sent the submitted phrases to an attacker-controlled Vercel domain.
Attack Chain
The figure below shows the attack chain for this campaign.

Figure 1: High-level overview of the campaign’s attack chain.
Technical Analysis
The following sections examine the campaign’s redirect chain, phishing page, and recovery phrase collection process.
ThreatLabz observed malicious sponsored ads in search results for Ledger-related terms. The ads targeted users in the United States, Europe, and parts of Asia. An example of a malicious Google ad is shown below.

Figure 2: Malicious Google ad impersonating Ledger in search results.
The ad displayed google.com and “10L+ visits in the past month” (“10L” means 1 million in Indian numbering). The visit count appears to refer to google.com rather than the phishing destination, which may have made the ad look more credible. The ad came from a long-standing, verified advertiser account with no observed history of malicious ads. The threat actor may have compromised the account to run the campaign.

Figure 3: Google’s advertiser information for the malicious Google ad, showing a verified advertiser identity and a location in Germany.
Clicking the malicious ad took users to a Google Cloud Storage URL, which redirected them to a Vercel-hosted page. That page then redirected users to a Google Sites page displaying the phishing page in an iframe. The attack also used Vercel-hosted domains to serve the phishing content displayed in the iframe. The Vercel domain in the JavaScript redirect appeared to change approximately every 15-20 minutes during our analysis, making the activity harder to detect based on the reputation of the domain.
The two HTML examples below show that the JavaScript redirect points to a different Vercel-hosted domain in the later sample.

Figure 4: The two HTML examples showing that the JavaScript redirect points to a different Vercel-hosted domain.
The phishing page mimicked the official Ledger interface and offered downloads for Windows, macOS, Linux, and mobile devices. The phishing page collected device metadata and monitored user interactions like keypresses, touches, and mouse movements. It sent this data to a Vercel-hosted endpoint, potentially allowing attackers to distinguish real visitors from automated analysis tools. The phishing page also included a Cloudflare Web Analytics beacon (beacon.min.js) configured with an analytics token. The phishing page is shown below.

Figure 5: The phishing page impersonating Ledger.
The phishing page allowed the user to select a device type when downloading the Ledger app, as shown below.

Figure 6: Ledger device options displayed on the phishing page.
After selecting a device, the user was presented with messages such as "Connecting your Ledger" and "Initializing Firmware Update." The phishing page then claimed that the Ledger device was connected and asked the user to confirm device ownership, as shown in the figure below.

Figure 7: Fraudulent prompt asking the user to confirm ownership.
The phishing page then prompted the user to enter their secret recovery phrase, as shown in the figure below.

Figure 8: Fraudulent secret recovery phrase entry interface with autocomplete feature.
A secret recovery phrase (SRP) allows a user to restore a cryptocurrency wallet. By stealing this phrase, attackers can restore the wallet in compatible software and transfer funds without access to the victim’s physical Ledger device. The phishing page retrieves the 2,048-word BIP-39 English wordlist from api/bip39-english.txt and uses it to provide autocomplete suggestions in each recovery phrase field. As the user types, a dropdown displays matching words from the list.
When the user first submitted their recovery phrase, the page sent it to an attacker-controlled Vercel domain. The page also initialized an hCaptcha widget in invisible mode during submission. The page then displayed an error message: “Invalid seed. Please re-enter your recovery phrase carefully.” After the user submitted the phrase again, the page sent the second submission to the attacker-controlled endpoint and redirected the user to the initial landing page. ThreatLabz did not observe server-side logic comparing the two submissions.
Conclusion
This campaign used malicious Google ads to direct Ledger users through Google Cloud Storage and Vercel to a Google Sites page displaying a phishing site in an iframe. The phishing site imitated Ledger’s interface and used a fake device-verification process to collect secret recovery phrases. The attackers were able to update parts of the delivery chain while continuing to use the same Google Cloud Storage page.
Zscaler Coverage
Zscaler’s multilayered cloud security platform detects indicators related to this phishing campaign at various levels with the following threat names:
Indicators Of Compromise (IOCs)
Type | Value |
|---|---|
GCS Bucket URL | storage[.]googleapis[.]com/apf-leg-ad-23798/ storage[.]googleapis[.]com/ledg-leg1-79230/ storage[.]googleapis[.]com/apf-leg-ad-22076/ storage[.]googleapis[.]com/apf-leg-ad-32595/ |
Google Sites URL | sites[.]google[.]com/view/start-ledger-wallet sites[.]google[.]com/view/apps-ledger-wallet sites[.]google[.]com/view/download-ledger-wallet-pc |
Vercel Domains | soyyoo-cwpc5n0e[.]vercel[.]app rpc-gbz5[.]vercel[.]app whyavc-qwmv6stx[.]vercel[.]app router-wdoi[.]vercel[.]app node-f1ey[.]vercel[.]app |
Was this post useful?
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.
Get the latest Zscaler blog updates in your inbox
By submitting the form, you are agreeing to our privacy policy.


