Active malicious phishing campaign targeting Uniswap users via search results and ads.
Security & Exploits ·
A malicious phishing campaign is actively targeting Uniswap users through manipulated search results and advertisements, according to security researcher Vladimir S. The attack exploits a technique called cloaking, in which ads pass moderation review for legitimate content but redirect users to malicious sites after approval. Attackers reportedly leverage ad trackers configured to switch destination URLs based on visitor IP addresses, allowing them to show safe content to automated moderators while funneling real users to attacker-controlled phishing pages.
The underlying tool enabling these campaigns is 1Campaign, a cloaking platform maintained by an operator using the handle DuppyMeister for over three years. The platform combines real-time visitor filtering, fraud scoring, and geographic targeting within a dashboard designed to bypass Google's ad screening policies. In one observed campaign targeting bitcoinhorizon.pro, the platform processed 1,676 total visitors but approved only 10—a 0.6% success rate—automatically blocking traffic from cloud providers and security infrastructure. The platform also includes an assistant for launching search campaigns that circumvent Google Ads policy restrictions.
What remains unclear is whether the specific vulnerabilities exploited in Google's moderation process—including the use of direct links without tracking parameters during review—have since been patched. The geographic scope and current volume of active campaigns remain unspecified.