Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?

你叔叔的 Mac 在浏览 Google 广告后显示“已中毒”并死机了,现在该怎么办?

Researchers say they recently found Google ads delivering a sophisticated tech support scam that freezes the screens of both Windows and Mac devices and displays messages urgently instructing them to phone a bogus call center. 研究人员表示,他们最近发现 Google 广告正在传播一种复杂的“技术支持诈骗”。该诈骗会使 Windows 和 Mac 设备屏幕死机,并显示紧急信息,诱导用户拨打虚假的客服中心电话。

The ads were displayed all over the web, including on high-traffic maps, weather, real-estate, document-hosting, and sports sites. Users who called the number were then urged to pay hefty fees, grant remote access to their devices, or divulge personal information. 这些广告遍布网络,包括高流量的地图、天气、房地产、文档托管和体育网站。拨打该号码的用户会被诱导支付高额费用、授予设备远程访问权限或泄露个人信息。

From August 31 to September 14, security firm Netskope observed users from 619 customer organizations click on the malicious ads, although none of them were actually scammed because Netskope blocked the content. Roughly 62 percent of the organizations were based in the US, with Japan and Australia accounting for the Nos. 2 and 3 spots. Since the firm has visibility into only a tiny sliver of Internet activity, the number of people exposed to the ads—including those who fell victim to it—is likely much higher. Netskope tracked more than 250 Google Ads campaign IDs across at least 284 legitimate publisher sites. 从 8 月 31 日到 9 月 14 日,安全公司 Netskope 观察到来自 619 个客户组织的用户点击了这些恶意广告,但由于 Netskope 拦截了相关内容,没有人真正受骗。约 62% 的受影响组织位于美国,日本和澳大利亚分列第二和第三位。由于该公司只能监测到互联网活动的一小部分,因此接触到这些广告的人数(包括那些已经受害的人)可能要高得多。Netskope 在至少 284 个合法发布商网站上追踪到了超过 250 个 Google 广告活动 ID。

So, what about Uncle Louie? “For the victim, that tradecraft turns an ordinary ad click into a browser that appears to seize up on a fake security warning,” Netskope said. “The locker fills the screen, hides the cursor, swallows the usual exit keys, and lags the browser, all to manufacture the sense of a broken machine and pressure the person into calling the number on the screen. Nothing on the computer is actually locked, but in the moment it is convincing enough to push people toward the scam.” 那么,路易叔叔(Uncle Louie)该怎么办?Netskope 表示:“对于受害者来说,这种手段将一次普通的广告点击变成了一个看似因虚假安全警告而死机的浏览器。锁定程序会填满屏幕、隐藏光标、屏蔽常用的退出键并导致浏览器卡顿,所有这些都是为了制造机器故障的假象,并迫使受害者拨打屏幕上的号码。电脑实际上并没有被锁定,但在那一刻,它足以让人信以为真,从而掉入诈骗陷阱。”

By now, many people, including a fair number of readers of this site, ridicule and shame people who fall for such scams. These criticisms fail to account for a sizable portion of Internet users who have little or no understanding of how computers and the Internet work. Combined with their need to get things done quickly and the growing difficulty of navigating the web, this lack of awareness makes a sizable portion of users prime targets. There’s little doubt that some critics have close friends and family who are among those who simply don’t know enough to be wary. 时至今日,许多人(包括本网站的不少读者)会嘲笑那些落入此类骗局的人。这些批评忽略了很大一部分互联网用户,他们对计算机和互联网的运作方式知之甚少。再加上他们需要快速完成任务的需求,以及日益复杂的网络环境,这种认知匮乏使相当一部分用户成为了主要目标。毫无疑问,一些批评者身边也有亲友属于那些因缺乏知识而无法保持警惕的人群。

Further making the scam convincing, the software kit that delivers the fake warnings is designed to be stealthy and closely mimic the signs of a real infection. The browser address bar no longer appears, the warning screen occupies the entire screen, and presses of escape and many other keys are disabled. The browser performance degrades, sounds play, and pages lag, giving the impression that something is seriously wrong. Messages urging the user not to restart the machine and to call a call center immediately flash. Attempts to close the browser only make the scam message refresh. The warnings appear only after a user makes a mouse movement. 为了让骗局更具说服力,发送虚假警告的软件工具包被设计得非常隐蔽,并极力模仿真实病毒感染的迹象。浏览器地址栏消失,警告页面占据整个屏幕,Esc 键和其他许多按键被禁用。浏览器性能下降、播放声音、页面卡顿,给人一种“出大事了”的错觉。屏幕上闪烁着警告信息,催促用户不要重启机器并立即拨打客服电话。尝试关闭浏览器只会导致诈骗信息刷新。只有在用户移动鼠标后,警告才会出现。

The software is also encrypted and only decrypted and then displayed in the browser memory. Both these conditions prevent many endpoint security wares—and possibly Google’s ad filters—from detecting the malice. Further, the warning ads appear differently depending on whether the targeted user device is running Windows or macOS. 该软件还经过加密,仅在浏览器内存中解密并显示。这两个条件使得许多终端安全软件(可能也包括 Google 的广告过滤器)无法检测到其恶意行为。此外,警告广告会根据目标用户设备运行的是 Windows 还是 macOS 而呈现出不同的形式。

Google didn’t say what caused its scanners to miss the scam campaign or give any indication the ads have been fully removed from its massive ad platform. “We have zero tolerance for scams,” the company said in a statement. “We’re actively investigating the campaigns in this report and will take action against accounts that violate our policies.” The company has said that last year it blocked over 99 percent of violating ads before they were ever served. Google 没有说明其扫描程序为何漏掉了这些诈骗活动,也没有表示这些广告已从其庞大的广告平台中完全清除。该公司在一份声明中表示:“我们对诈骗行为零容忍。我们正在积极调查本报告中的活动,并将对违反我们政策的账户采取行动。”该公司曾表示,去年其拦截了超过 99% 的违规广告,使其未能投放。

As Netskope noted, devices aren’t actually locked up, even though most of the usual keys for closing the scam window have been disabled. In this case and many similar ones, users can still easily exit the window. For both Windows and macOS devices, this can be done in most cases by pressing the escape key and holding it for several seconds. The press will force the browser out of full screen and release the keyboard lock, and from there, the tab can be closed. 正如 Netskope 所指出的,设备实际上并没有被锁定,尽管大多数用于关闭诈骗窗口的常用按键已被禁用。在这种情况下以及许多类似案例中,用户仍然可以轻松退出窗口。对于 Windows 和 macOS 设备,大多数情况下只需按住 Esc 键几秒钟即可。此操作会强制浏览器退出全屏并解除键盘锁定,随后即可关闭该标签页。

An alternative approach is to invoke the Windows Task Manager (control-shift-escape) and exit the browser. On a Mac, the keys are (cmd-option-escape). In both cases, users can reopen the browser without restoring the previous session. No legitimate company will ever advise users to call a phone number when they’re infected. Under no case should people hit by tech support scams call the number. Those who provide informal tech support for friends and family might consider writing the above advice on a Post-it and affixing it to screens. 另一种方法是调出 Windows 任务管理器(Ctrl+Shift+Esc)并强制退出浏览器。在 Mac 上,快捷键是(Cmd+Option+Esc)。在这两种情况下,用户都可以重新打开浏览器,而无需恢复之前的会话。任何正规公司都不会建议用户在中毒时拨打某个电话号码。无论如何,遭遇技术支持诈骗的人都不应拨打该号码。那些为亲友提供非正式技术支持的人,不妨考虑将上述建议写在便利贴上,贴在他们的屏幕上。