Human uncovers Pushpaganda ad fraud in Google Discover

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Human's Satori Threat Intelligence and Research Team identified the Pushpaganda campaign, which uses SEO and AI‑generated content to push deceptive news into Google Discover and lure users into enabling persistent browser notifications that deliver scareware.
- Pushpaganda generated roughly 240 million bid requests across 113 domains in a seven‑day period, initially targeting India and later expanding to the U.S., Australia, Canada, South Africa, and the U.K.
- Google has rolled out a fix to address the spam issue in Discover and says it maintains robust spam‑fighting systems and policies against low-quality, manipulative content.
- Infoblox previously reported a similar push‑notification abuse campaign called Vane Viper in September 2025, showing that this tactic is not new.
- Low5 operation, uncovered earlier by HUMAN, demonstrated that cash‑out domains can be reused by other actors after a specific fraud campaign is shut down, highlighting the resilience of the monetization infrastructure.
- Louisa Abel and her colleagues noted that the AI‑generated news stories in the Pushpaganda scheme are deceptive and that the ad traffic on the compromised sites generates illicit revenue for the scammers.
- Android users receive the deceptive Discover feed, and the push notifications they enable can redirect them to additional malicious sites, creating organic traffic for ads embedded there.
Why it matters: Victims lose money and privacy when tricked into enabling malicious push notifications, while advertisers unknowingly fund fraudulent ad impressions; Google’s swift fix curtails the specific spam surge, but the underlying cash‑out infrastructure remains reusable, allowing other threat actors to reuse the same domains for future scams.

