Malvertising (malicious advertising) is the use of online ads to spread malware or lead users to phishing and scam websites.
How malvertising works
Criminals buy ads through legitimate advertising networks or hijack existing advertiser accounts. Their ads appear on trusted news sites and, increasingly, at the top of search results. Typical schemes:
- Fake software downloads – an ad for “Notepad++”, “KeePass”, “Zoom” or a crypto wallet leads to a lookalike site that serves an installer bundled with an infostealer or remote access trojan.
- Phishing – ads for banks or webmail lead to phishing pages, often on typosquatted domains.
- Drive-by attacks – malicious ad code redirects visitors to exploit kits or fake browser update pages.
- Scams – fake investment platforms and tech support pages.
Attackers use cloaking: moderators and security scanners see a harmless page, while real victims from selected countries get the malicious one.
Why malvertising matters
Victims do nothing unusual – they search for a well-known program and click the first result. Because the ad appears on a legitimate platform, it inherits its trust. Malvertising has become one of the main delivery channels for malware aimed at both home users and IT staff downloading admin tools.
How to protect yourself
- Download software only from official websites or app stores, and check the domain carefully.
- Skip sponsored results when searching for downloads, or use an ad blocker.
- Companies can block ad domains via DNS filtering and restrict software installation.
- Keep browsers and plugins updated to stop drive-by exploits.