What Is Malvertising?
Malvertising, short for malicious advertising, is the practice of injecting malware or malicious code into legitimate online advertising networks. Attackers buy ad space or compromise existing ads, then use the advertising ecosystem itself to deliver exploit code, malicious redirects, or convincing lures to users browsing trusted, mainstream websites.
That last part is what makes malvertising effective: victims do not need to visit shady corners of the internet. A malicious ad served on a reputable news site or in sponsored search results can compromise a device or steal credentials from users who did everything “right.”
How Malvertising Works
The online advertising ecosystem is a complex chain of advertisers, ad networks, exchanges, and publishers, with ads bought and placed through automated real-time bidding. Attackers exploit this complexity in a few recurring ways:
- Posing as legitimate advertisers. Threat actors create fake companies and submit clean-looking ads that pass network review, then swap in malicious payloads or destinations after approval.
- Compromising the chain. Attackers inject code into legitimate ad creatives, third-party ad scripts, or smaller ad networks with weaker vetting.
- Abusing targeting. The same targeting tools built for marketers let attackers aim malicious ads at specific regions, industries, or search keywords, such as ads impersonating popular software downloads in sponsored search results.
Once served, the malicious ad either attacks the browser directly, redirects the user through a chain of intermediary pages to an attacker-controlled site, or lures the user into downloading trojanized software that connects back to a C2 server.
Malvertising vs. Adware
The two are frequently confused, and the distinction is simple. Adware is unwanted software installed on a user’s device that displays ads and tracks activity; the problem lives on the endpoint. Malvertising is an attack delivered through the advertising ecosystem itself; the problem lives in the ad supply chain, and a completely clean device can be victimized simply by loading a page. Adware is an infection you carry with you, while malvertising is a trap placed in otherwise legitimate content.
Types of Malvertising Attacks
How a malicious ad reaches a victim: injection, delivery, redirect, payload.
Drive-By Downloads
The most dangerous variant. Malicious ad code exploits vulnerabilities in the browser or its plugins to download and execute malware without any user interaction. Simply rendering the ad is enough, which is why keeping browsers patched matters so much.
Redirect-Based Malvertising
The ad forcibly redirects the browser, often through several hops, to phishing pages, fake software updates, tech support scams, or exploit landing pages. Redirect chains help attackers evade ad network scanning, since the initial destination looks clean.
Exploit Kits
Redirects frequently terminate at an exploit kit: a toolkit that fingerprints the visitor’s browser, identifies unpatched vulnerabilities, and automatically fires the matching exploit to install malware such as infostealers or ransomware loaders.
Real-World Malvertising Examples
Malvertising has repeatedly reached massive audiences by compromising major ad platforms. High-profile campaigns have served malicious ads on top-tier news and entertainment sites, delivering ransomware through exploit kits at the peak of the Angler era. More recently, attackers have leaned heavily on search engine malvertising: sponsored results impersonating popular tools such as remote access software, browsers, and IT utilities, delivering trojanized installers that drop infostealers and loaders. Fake browser update overlays, served through compromised ad slots, remain a staple initial access technique for multiple threat groups.
Why Malvertising Is Hard to Detect
Ads are dynamic by design. The same ad slot serves different content to different users, selected in milliseconds through real-time bidding across a chain of intermediaries. Attackers exploit this by serving clean content to scanners and security researchers while serving payloads only to targeted victims, rotating domains and creatives constantly. Publishers rarely see the ads running on their own pages, and users have no way to distinguish a malicious ad from a legitimate one before interacting with it.
How to Protect Against Malvertising
For End Users
- Keep browsers, operating systems, and plugins fully patched to neutralize drive-by exploits.
- Use reputable ad blocking or script control where policy allows, and enable browser protections against deceptive sites.
- Treat sponsored search results for software downloads with suspicion; navigate to vendor sites directly.
- Never install “updates” prompted by a webpage overlay.
- Run endpoint protection capable of blocking malicious redirects and payloads.
For Website Owners and Ad Networks
- Vet advertising partners and prefer networks with strong creative scanning and advertiser verification.
- Continuously scan served ad creatives and monitor for unexpected redirects originating from ad slots.
- Enforce restrictive Content Security Policy and sandbox ad iframes to limit what ad code can do.
- Establish rapid takedown procedures with ad partners for reported malicious creatives.
How SOCRadar Monitors Malvertising-Related Threats
Malvertising campaigns depend on infrastructure: lookalike domains, fake download portals, and redirect hosts. SOCRadar’s Brand Protection detects impersonating domains and fraudulent sites that abuse your brand in malicious ads, and supports takedown of the infrastructure behind them. Cyber Threat Intelligence tracks the campaigns, C2 servers, and malware families distributed through malvertising, while Dark Web Monitoring surfaces the sale of the infostealer logs these campaigns produce, revealing when your users or customers have been caught by one.
FAQ
Can I get infected by a malicious ad without clicking it?
Yes. Drive-by download attacks exploit browser vulnerabilities as the ad renders, requiring no interaction. Fully patched browsers dramatically reduce this risk.
Is malvertising the same as adware?
No. Adware is unwanted ad-displaying software on your device, while malvertising is malicious content delivered through legitimate ad networks to any visitor of an affected page.
Why do legitimate websites serve malicious ads?
Publishers outsource ad selection to automated networks and exchanges. When attackers slip malicious creatives into that supply chain, even reputable sites unknowingly serve them.
What is the most common malvertising technique today?
Search engine malvertising: sponsored results impersonating popular software brands and delivering trojanized installers, typically carrying infostealer malware.
