A malvertising campaign, which was active since April 21, was established by hackers for a popular remote desktop application, AnyDesk. A fake app ad was pushed via Google ads when searching for “AnyDesk”. The App contained trojan malware that could control the victim’s computer. That ad redirected users to a URL: https://domohop.com/anydesk-download/ which then downloads the trojan file with link: https://anydesk.s3-us-west-1.amazonaws.com/AnydeskSetup.exe
40% of these ads lead to downloading and installing this trojan file. And 20% of these installations lead to getting a follow-on hands-on-keyboard activity. Hackers have reportedly paid Google $1.75 per click.