Technique
Malvertising
Also known as: Malicious Advertising, Malicious Online Ads, Drive-by Download Advertising, Ad-based Malware Distribution
Malvertising (malicious advertising) injects malware through legitimate ad networks, delivering payloads via infected display ads, pop-ups, or sponsored search results—often without requiring user clicks through drive-by downloads.
Common attack flows
How it fits in a scam
Before
This is often where the scam begins.
Defense
How to defend against this
How to spot it
- Ads with spelling errors or grammatical mistakes or low-quality graphics
- Unrealistic offers like free prizes or urgent security warnings or too-good-to-be-true deals
- Sponsored search result URLs that don't match advertised brand with subtle typos
- Unexpected browser redirects to unfamiliar websites
- Pop-ups appearing from unexpected sources on legitimate sites
- Browser suddenly slowing or behaving erratically after viewing ads
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading
Malwarebytes
Consumer guide to malvertising definition and protection
CrowdStrike
Attack types and real-world examples including Angler, RoughTed, KS Clean
FBI IC3
2022 PSA warning about criminals using search ads to impersonate brands
CISA
Capacity Enhancement Guide for browser security against malvertising