Key Takeaways
Malvertising delivers malware or scam redirects through legitimate, verified ad networks.
Ad blockers and endpoint protection reduce exposure, but tracking the infrastructure behind campaigns catches threats earlier.
Group-IB’s Threat Intelligence and Incident Response services help organizations detect malvertising infrastructure early and contain incidents that get through.

What Is Malvertising?

In its simplest form, malvertising is malicious code or a scam redirect delivered through an online advertisement. The word is a portmanteau of “malicious software” and “advertising.” It covers attacks that use ads to spread malware, potentially unwanted programs (PUPs), and other scams that harm users and businesses.

This distinction is part of the malvertising definition itself: it typically does not require breaching the publisher’s site. Instead, attackers compromise a link in the advertising supply chain, such as a hijacked advertiser account, a compromised ad server, or hijacked publisher ad tags, to insert malicious code into ads the site would otherwise legitimately serve. This distinction explains why it can appear on well-known news sites and streaming platforms and affect all types of devices.

How Malvertising Works

Malvertising exploits the same automated, real-time process that places legitimate ads on websites. This means attackers can reach victims without breaching a network, and the ad looks identical to an ordinary pop-up or paid placement, even though it carries malicious code.

The typical attack chain looks like the following:

  1. An attacker buys ad inventory or compromises an existing advertiser account with a clean history.
  2. The ad passes automated review by showing reviewers a clean version, then switches to the malicious code after approval.
  3. The ad is placed on legitimate, high-traffic websites through real-time bidding. 
  4. From here, the attack plays out in one of two ways. Clicking the ad redirects the user to a page with a fake, urgent prompt, a social engineering tactic designed to pressure quick action. Alternatively, simply loading the infected page can trigger an automatic drive-by download that exploits a browser or software vulnerability, infecting the device without any user action.
  5. The exchange or publisher eventually detects and removes the ad. But by then, it may have reached millions of impressions. 

Common Malvertising Attack Techniques

Malvertising attack techniques generally fall into two categories. Some exploit the browser directly, while others rely on convincing the user to take an action. 

Drive-by downloads 

A drive-by download installs malware as soon as a user’s browser loads the malicious ad, without any user action. It exploits vulnerabilities in the browser or a plugin to run code silently in the background.

Fake software update advertisements 

Fake software update advertisements mimic routine prompts, such as updates to a browser, media player, or plugin. Clicking “update” installs a trojanized installer containing an infostealer or backdoor access, instead of the real software. 

Tech support scam ads 

Tech support scam ads display an urgent, fake warning claiming the user’s device is compromised, paired with a phone number or chat redirect. The goal is direct financial fraud, not malware, as the scammer poses as a technician and convinces the user to install remote access software or pay for fake repairs. 

Fake browser alerts 

Fake browser alerts mimic legitimate system or security notifications, prompting the user to grant access by allowing push notifications or downloading a fix. Once permission is granted, attackers push a steady stream of scam ads directly to the device, bypassing the original ad network entirely. 

Cryptocurrency scam advertisements 

Cryptocurrency scam advertisements promote fake wallets, exchanges, or token giveaways, usually by impersonating well-known brands. Victims lose funds either by entering their wallet credentials on a fake site or sending funds directly, both irreversible actions once the transaction clears. 

Malvertising Examples 

The malvertising examples below define common attack techniques, then show how each plays out in real campaigns and how some patterns keep resurfacing across different attacks.

Fake CAPTCHA campaigns 

Fake CAPTCHA pages are a type of malicious ad that redirects the user to a page displaying a convincing but fake CAPTCHA. Solving it instructs the user to open a system command tool, such as the Run dialog on Windows or Terminal on macOS, and paste a command, which triggers a multi-stage script that installs an infostealer. 

Since August 2024, Group-IB’s Threat Intelligence team has tracked thousands of these fake CAPTCHA pages and identified Lumma as the most frequently distributed infostealer. In one documented case, malicious ads on pirated video and movie download sites redirected users to a fake CAPTCHA page, where solving said CAPTCHA triggered a PowerShell script that installed Lumma on the victim’s device. Read the full ClickFix research for the technical breakdown. 

Fake browser update campaigns 

Fake browser update campaigns push the same trojanized-installer technique through ad-supported streaming and download sites, prompting users to “update” their browser to keep watching.

The Federal Bureau of Investigation (FBI), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released a #StopRansomware joint advisory highlighting this technique. Interlock ransomware actors disguised malicious payloads as fake Google Chrome and Microsoft Edge browser updates, later shifting the payload filenames to impersonate security software updates once the browser-update lure became more widely recognized.

Search engine sponsored ad abuse 

Search engine sponsored ad abuse places malicious ads at the top of search results for popular software, brands, or services. A user searching for a legitimate tool may see a sponsored result outrank the real vendor’s site, leading to a convincing clone that delivers malware.

The FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement in December 2022 warning about cybercriminals buying search engine ad placements to impersonate well-known brands. These sponsored ads appeared above the legitimate company’s own search results, with minimal visual distinction from organic listings, and directed victims to malicious sites that installed ransomware or harvested login and financial credentials.

Malware distributed through legitimate websites 

Legitimate websites do not need to be compromised for malvertising to succeed. A site can unknowingly serve a malicious ad through its regular ad exchange, with no indication that anything is wrong until user reports start coming in.

The same #StopRansomware joint advisory mentioned previously documented this tactic in action. The FBI observed Interlock actors gaining initial access through drive-by downloads hosted on compromised legitimate websites, an atypical method for a ransomware operation, since most ransomware groups prefer phishing or exposed remote access services. 

How to Prevent Malvertising Attacks

Preventing malvertising attacks requires a mix of technical controls and awareness, since some techniques require no user action while others rely entirely on social engineering.

1. Keep browsers and software updated

Updated browsers and software prevent malvertising by closing the unpatched vulnerabilities drive-by downloads rely on to run code silently. Schedule regular security patches and remove outdated software that is no longer in use or supported.

2. Use ad blocking and web filtering

Ad blocking and web filtering prevent malvertising by stopping known malicious domains and malvertisements before a page loads them. This works best against drive-by downloads, but social engineering-based scams can still get through if a user is convinced to act on them directly.

3. Deploy endpoint protection

Endpoint protection prevents a malvertising payload from executing after it reaches the device. Endpoint Detection and Response (EDR) solutions use behavioral analysis and machine learning to scan for unusual activity, identifying and isolating threats before they spread further.

4. Train employees to identify suspicious ads

Trained employees can detect social engineering tactics that technical controls miss. Teaching specific red flags, not generic warnings, cuts risk far more effectively. Training should cover verifying software sources, recognizing ad-triggered update prompts, and scrutinizing unexpected messages before clicking on links. 

5. Enable DNS and network security controls

DNS servers and network security controls prevent malvertising by blocking known malicious domains and interrupting connections to command-and-control servers before a redirect ever reaches the browser. 

6. Monitor threat intelligence

Monitoring threat intelligence prevents malvertising by identifying the infrastructure attackers reuse across campaigns before it reaches users. A threat intelligence platform automates this by continuously tracking the domains, redirect chains, and malware families behind active threats. 

Infrastructure and tactics shift constantly, so defenses must adjust continuously to keep up. The Group-IB Threat Intelligence platform provides this visibility, giving security teams the context to block known malicious infrastructure before it reaches users. 

Malvertising vs Adware

Malvertising is malicious code delivered through a legitimate ad network to attack the user viewing the ad. Adware, also known as advertisement-supported software, is malicious software already installed on a device that generates revenue for its developers by automatically displaying ads, usually within a web browser. 

The table below compares malvertising and adware by how they spread, their primary goals, and the appropriate response.

Malvertising Adware 
How it spreads Spreads through a legitimate, verified ad network Spreads through bundled downloads or phishing links, then shows unwanted ads and redirects search requests
Primary goal Delivers malware, steals credentials, or redirects to a scam Generate ad revenue or hijack user browsing sessions
Response required Addressing the ad network or campaign delivering it Cleaning the infected device

Detecting Malvertising With Sandboxing, Continuous Monitoring, and Threat Intelligence 

Malicious ads move through programmatic real-time bidding (RTB) too fast for manual review. A single creative can win an auction, deliver a payload to a user, and disappear within one page load, so security teams need more than one detection method. 

Most mature detection programs work in three layers: detonating the creative to see what it does, monitoring ads the way a real user would to defeat evasion, and tracking the infrastructure that links one campaign to the next.

Detonating ad creatives in a sandbox

Security teams analyze suspicious ad creatives by detonating them within a sandbox to observe their behavior safely before the ads reach live traffic. 

  • An instrumented, isolated environment captures forced redirects, drive-by download attempts, and the exploit kits or social engineering pages the ad reaches.
  • Detonation exposes the full redirect chain, the sequence of intermediary domains, and traffic distribution systems that route a click from impression to final payload.
  • The malicious logic usually lives in that chain, not the visible banner. Following each hop reveals more than inspecting the creative alone.

Defeating cloaking with synthetic monitoring

Synthetic monitoring combats cloaking by watching ads the way a real user would, not the way an automated scanner does.

  • Most malvertising campaigns fingerprint each visitor by device, operating system, browser, referrer, geography, and IP reputation. The malicious payload is served only to targeted profiles, while others see a clean ad.
  • A scan from a data-center IP running a headless browser typically sees the clean version of an ad. Synthetic monitoring counters this by rotating residential and mobile IP addresses, device profiles, and locations until the campaign reveals its real behavior.
  • Group-IB Digital Risk Protection platform applies this approach across ad networks, search engines, and social platforms to surface rogue ads abusing an organization’s brand.

Blocking campaigns through threat intelligence

Threat intelligence lets teams block a malvertising campaign before a single creative is analyzed by matching observed infrastructures against known malicious indicators.

  • Feeds flag domains, IP ranges, TLS certificates, and traffic distribution systems attackers reuse across campaigns. A new ad running on recycled infrastructure gets stopped based on overlap alone.
  • These Indicators of Compromise (IoCs) also drive retrospective hunting, tracing a newly found domain back through earlier campaigns to related infrastructure. 
  • The Group-IB Threat Intelligence platform maps this attacker infrastructure and tracks reuse patterns, linking one operation to the next.

Business Impact of Malvertising

The business impact of malvertising includes account takeover via stolen credentials, reputational damage from brand impersonation, and slower incident containment when no incident response plans are in place. 

Account takeover

Credential theft from an infostealer can lead directly to an account takeover. If the infected device belongs to an employee, it can open the door to further compromise within the corporate network. 

Reputational damage

Customers who fall victim to fake brand ads often blame the company rather than the scammer, eroding trust for a risk the business did not create. 

The Federal Trade Commission (FTC) reported that imposter scams, including business impersonation,  were the most reported fraud category in the U.S. in 2025, with business impersonation losses alone reaching $1 billion. 

Slower containment

A malvertising compromise without a prepared incident response plan costs security teams valuable time, delaying their ability to identify the compromise and cut off attacker access.

How Group-IB Helps Prevent Malvertising Attacks

Group-IB helps organizations prevent malvertising attacks through three connected capabilities: tracking the infrastructure behind campaigns before they reach users, detecting and taking down malicious ads that impersonate their brand, and responding quickly when a payload does get through. 

Group-IB Threat Intelligence platform helped a client uncover malvertising infrastructure invisible to their existing monitoring tools, tracing redirect chains back to infrastructure reused across multiple campaigns. This gave the client’s security team the context to block the threat at its source rather than reacting to each new domain. Read the full case study, Under the Hood Part 2, to see how continuous infrastructure tracking can catch what generic monitoring misses.

For malvertising that impersonates a company’s own brand, such as sponsored ad abuse and brand impersonation, Group-IB Digital Risk Protection identifies and takes down malicious ads and fake domains across web, social, and dark web channels before they cause lasting reputational damage. 

If a malvertising campaign does result in a compromise, Group-IB’s Incident Response team is available around the clock to contain the threat, investigate the root cause, and support recovery.

Group-IB is Verified by TAG, the digital advertising industry’s initiative for vetting companies against fraud, malware, and malvertising. This status confirms Group-IB’s identity through a proprietary background check, a standard the ad industry uses to select trusted security partners.

Contact Group-IB experts to learn how Threat Intelligence can track malvertising infrastructure before it reaches your users.

 

Frequently Asked Questions

What types of malware are commonly delivered through malvertising?

arrow_drop_down

Malvertising commonly delivers infostealers, trojanized installers, and remote access tools. Fake CAPTCHA and fake update campaigns are among the most active delivery methods for infostealer malware.

 

Can malvertising infect a device without clicking an ad?

arrow_drop_down

Yes, malvertising can infect a device without the user clicking an ad. Drive-by download ads execute as soon as a page loads, exploiting a browser or plugin vulnerability without requiring a click. 

 

What is the difference between malvertising and phishing?

arrow_drop_down

Malvertising delivers its payload through a legitimate ad network. Phishing relies on deceptive messages, such as emails, to trick a user into clicking a malicious link or sharing private credentials.

 

How does malvertising get past ad network security checks?

arrow_drop_down

Attackers bypass security checks by submitting a clean ad for review, then switching to a malicious version after approval. Some attackers delay activation until the ad has built a trusted history with the exchange platform. 

 

Are ad blockers enough to protect against malvertising?

arrow_drop_down

Ad blockers may stop some malicious ads, but they can’t catch social engineering techniques, such as tech support scams or fake CAPTCHA pages, because these rely on user action rather than ads loading malicious code directly.

 

How do cybersecurity teams detect malvertising campaigns?

arrow_drop_down

Cybersecurity teams combine sandbox analysis of suspicious ad creatives, traffic anomaly monitoring, and threat intelligence on known malicious infrastructure to detect campaigns before they scale. 

 

Which devices and browsers are most vulnerable to malvertising?

arrow_drop_down

Devices running outdated browsers or plugins are the most vulnerable, as many malvertising techniques exploit unpatched vulnerabilities. Mobile devices are increasingly targeted as well, particularly through fake apps and fake update ads. 

 

What should you do if you suspect a malvertising attack?

arrow_drop_down

If you suspect you’ve been a victim of a malvertising attack, disconnect the affected device from the network and run a full endpoint scan. Report the malicious ad to the hosting website and ad network using an uncompromised device. In a corporate environment, engage your incident response team immediately to contain and investigate the incident. 

 

Group-IB: Fight
against cybercrime