Gadscare.com Uses Fake Robot Check
While investigating suspicious websites, our researchers came across the gadscare.com malicious page. The primary objective of this webpage is to engage in browser notification spam and redirect users to other potentially harmful or unreliable sites. Typically, visitors land on such pages through redirects generated by websites utilizing illegitimate advertising networks.
The specific content encountered on rogue webpages can vary depending on the geolocation of the visitors' IP address. When we accessed gadscare.com, it presented a deceptive instruction stating, "Click 'Allow' if you are not a robot." This fraudulent CAPTCHA verification is designed to trick visitors into granting the site permission to send browser notifications.
If users grant permission, gadscare.com proceeds to bombard them with advertisements promoting online scams, untrustworthy or hazardous software, and even malware. Consequently, by encountering websites like gadscare.com, users become susceptible to system infections, severe privacy breaches, financial losses, and identity theft.
How Can Misleading Websites Like Gadscare.com Abuse Push Notifications to Spam Ads?
Misleading websites like Gadscare.com exploit push notifications to spam ads by taking advantage of the notification feature offered by web browsers. Here's how they abuse push notifications:
Deceptive permission request: When users land on misleading websites, they are prompted with a deceptive message, often disguised as a CAPTCHA verification or a content access request. The message urges users to click on the "Allow" button, leading them to believe they are granting access to desired content or verifying their human identity. In reality, they are unknowingly giving permission for the website to send push notifications.
Permission granted for push notifications: If users fall for the deceptive request and click "Allow," the misleading website gains permission to send push notifications to the user's browser. These notifications can appear on the desktop or mobile device, even when the user is not actively browsing the website.
Persistent ad spamming: Once permission is granted, the misleading website exploits it to send a barrage of unwanted and intrusive advertisements directly to the user's device. These ads can promote scams, dubious software, fraudulent offers, or even contain malicious links leading to malware-infected websites.
Continuous notifications: Misleading websites often configure their push notification system to send frequent or continuous notifications, bombarding users with a stream of unwanted ads. This can disrupt the user's browsing experience, distract them from their activities, and create a nuisance.
Difficult to disable notifications: Disabling push notifications from misleading websites can be challenging for users who have unwittingly granted permission. The websites may employ tactics to make it difficult for users to locate and disable the notifications, such as hiding the notification settings or constantly re-enabling them after the user attempts to disable them.







