Inside the 'Thank You from Google' Surge: Legitimate Rewards or Dangerous Malvertising?
The infrastructure driving the lucky visitor pop-up campaign mirrors the covert operations that have plagued mobile marketplaces for years. Much like the programmatic abuses that led to the expulsion of utility applications like ES File Explorer from the Play Store after investigations uncovered automated click fraud schemes, today's malvertising syndicates construct layered systems designed to game automated review systems.
Threat actors utilize cloaking services. When Google's ad safety crawlers inspect a programmatic ad tag, the server responds with a benign, static creative advertising a local service or generic retail brand. When a residential IP address with a standard mobile user-agent hits that same ad unit, the server returns a malicious payload. The script hijacks the browser's view, cycling through compromised content delivery networks to obscure the origin before presenting the fake Google prize alert.
On mobile platforms, the campaign frequently co-opts rogue notification permissions. Attackers prompt the user with a deceptive verification dialog: "Click Allow to verify you are not a robot." Granting permission registers an unauthorized service worker. Days or weeks later, long after the user leaves the original website, the browser begins pushing system-level alerts disguised as official Google OS notifications, declaring that rewards are waiting to be claimed.