From what I have seen I think what they do is they make the website acceptable first in Google's ad placement standards and when their ads are up and running in their search engine this is the time where they change their website and turn it into a phishing website that is why they somehow bypass the security Google is trying to implement. If Google wants to improve on this kind of matter I think the best way to do it is to constantly monitor the changes happening from that link to see if there is something suspicious going on with what they are advertising.
Yeap,, this is how they get the approval for their Ads first and replace the phishing one after that. Although i am not sure about google recent ad rules but they go for initial review after getting report from anyone. In most cases this type of website owners follow strong SEO to bring their website on top suggests list.
To keep safer from these traps i always prefer to bookmark the real website for regular use but most new crypto user usually like to use browsers search bar.