Malvertising, a blend of "malicious" and "advertising", is the use of paid online ads to deliver malware, steal credentials or push users to fraudulent pages. It exists because advertising is the cheapest way to put code in front of a large audience on websites people already trust. An attacker who buys an ad slot does not need to hack the BBC or The New York Times; the ad system carries the payload there on the attacker's behalf.
The term covers two broad families. In display malvertising, a creative served through programmatic pipes carries code that redirects, fingerprints or exploits the browser. In search malvertising, a paid listing impersonates a real brand and sends people to a lookalike site offering a fake download or login page.
How an attack works
A display campaign usually starts with a front. Attackers set up what appears to be a legitimate advertiser or agency, buy inventory through an ad network, demand-side platform (DSP) or supply-side platform (SSP), and run clean creatives for long enough to pass review. The malicious behaviour switches on later, often for a fraction of traffic.
Confiant, a creative security vendor, described the pattern in January 2018. A group it called Zirconium operated 28 fake ad agencies, 20 of them active, and served roughly 1 billion ad impressions during 2017. Only a "small portion" of the traffic it bought received a payload, according to Confiant. That selectivity is the core technique.
Cloaking does the selecting. A script inside the ad, or on a server behind it, fingerprints the visitor's device, browser and network. Security scanners, bots and researchers see an innocent page, sometimes called a "white page". Real users matching the target profile see the attack. In the Morphixx revival detected by GeoEdge in September 2024, malicious code was hidden in a jQuery file served through Google's ad server, with fingerprinting moved into the banner's pre-loading stage so the attacker controlled both the banner and the landing page.
The payload then takes one of several forms. Forced redirects navigate the whole page, without a click, to a scam, a fake prize or an app store listing. Confiant defined a malicious ad in its quality reporting as a creative containing "usually obfuscated JavaScript" that triggers a forced redirect or loads a secondary payload. Drive-by downloads, common in the exploit-kit era, used browser or plugin vulnerabilities to install software with no click at all. Fake downloads and phishing pages rely on the user acting.
Search malvertising follows a different path. An advertiser account, often stolen or newly verified under false details, bids on a brand or software name. The ad displays the brand's logo and URL, then routes clicks through a filtering domain. Malwarebytes researcher Jerome Segura documented an October 2023 Google ad for the KeePass password manager that led to xn--eepass-vbb.info, a Punycode domain rendering as a near-identical spelling. "The difference between the two sites is visually so subtle it will undoubtably fool many people," Segura wrote. The installer carried FakeBat malware.
The newest variants avoid shipping a finished file at all. In SourTrade, documented by Confiant and researcher Michael Steele on July 23, 2026, the landing page sends the browser a recipe to assemble a unique Windows executable locally, using a legitimate Bun runtime and a session-specific seed. Each victim receives a different file, so hash-based detection has nothing consistent to match. The campaign impersonated TradingView, Solana and Luno across 12 countries and 25 languages.
Origin and evolution
The first widely recorded cases date to late 2007 and early 2008, when ads exploiting an Adobe Flash vulnerability appeared on MySpace, Excite and Rhapsody. On September 13, 2009, NYTimes.com warned readers about an "unauthorised advertisement" that displayed fake virus alerts and pushed rogue security software, according to The Register.
Washington took notice in 2014. The US Senate Permanent Subcommittee on Investigations, chaired by Carl Levin with John McCain as ranking member, published "Online Advertising and Hidden Hazards to Consumer Security and Data Privacy" on May 14, 2014. It cited malware served to Yahoo users in December 2013 and through YouTube ads in February 2014, and noted that a typical ad passed through five or six intermediaries before reaching a browser.
The industry's main collective response followed. The Trustworthy Accountability Group (TAG), founded by the 4A's, the ANA and the IAB in September 2014, launched its anti-malware certification on November 15, 2016, and awarded the first nine seals on July 31, 2017.
Exploit kits peaked in March 2016, when a campaign using RIG and Angler reached visitors of the BBC, The New York Times, MSN and AOL through networks including Google, AppNexus and Rubicon, according to Help Net Security. Browsers then removed the easiest techniques. Chrome 64, released in January 2018, blocked redirects initiated from third-party iframes unless the user had interacted with the frame. The HTML standard's sandbox attribute gives publishers a similar control: the "allow-top-navigation-by-user-activation" keyword lets a framed ad navigate the page only after a user gesture. The IAB's SafeFrame 1.0, unveiled on March 19, 2013, added a managed container that limited what ad code could reach on the host page.
Attackers responded by moving away from exploits and towards deception. GeoEdge reported in April 2019 a WebRTC-based malvertising technique delivered mostly through header bidding, detectable only through behavioural analysis. By late 2022, search ads had become a primary channel. The FBI's Internet Crime Complaint Center issued a public service announcement on December 21, 2022, warning that criminals were buying search ads to impersonate brands and distribute malware and ransomware.
Why it matters for marketers
Malvertising is a supply-chain problem. Each malicious impression is delivered by the same pipes that carry legitimate campaigns, so publishers, SSPs and exchanges absorb the reputational damage. Confiant's report for the second quarter of 2019, covering more than 120 billion impressions, put the malicious ad rate at 0.25%, and found the worst major SSP over 60 times as likely to deliver one as the best. The rate on Sundays, 0.44%, was more than three times the Thursday rate of 0.13%.
Brands are victims twice. Their names are used as bait, and their legitimate ads compete with impersonators bidding on the same keywords. Google tightened its Misrepresentation policy to suspend impersonating advertisers immediately and permanently from March 2024.
Platform figures show the scale but not the outcome. Google's Ads Safety Report for 2025, published on April 16, 2026, recorded more than 8.3 billion ads blocked or removed and 24.9 million advertiser accounts suspended. Its largest category, abusing the ad network, which includes malicious software, accounted for 1.29 billion ads. That compares with 5.5 billion ads and 12.7 million accounts for 2023.
Limitations and disputes
The boundaries of the term are contested. Security researchers often restrict malvertising to ads that deliver malware or forced redirects. Regulators and consumer groups use it more loosely for scam ads, including deepfake investment pitches that install nothing. The distinction matters, because the scanning tools built for one do little against the other.
Detection is structurally behind. Creative scanning, offered by vendors such as Confiant, GeoEdge and The Media Trust, renders ads in controlled environments and watches what they do. Cloaking exists specifically to defeat that. Google says more than 99% of violating ads are stopped before serving; the Video Advertising Bureau has noted that the report offers limited visibility into the remainder, which on Google's own numbers could be as many as 83 million ads, a ceiling rather than an estimate.
Incentives are questioned too. A Reuters investigation in November 2025 reported internal Meta projections that about 10% of 2024 revenue, roughly $16 billion, came from scam and banned-goods ads, and that suspected fraudsters below a 95% certainty threshold were charged higher prices rather than removed. Meta spokesman Andy Stone called the figure "rough and overly-inclusive".
The remedies also cause friction. The FBI's 2022 advice recommended ad-blocking extensions, a position that sets consumer security against publisher revenue. Sandboxing iframes can also break legitimate rich media.
Not the same as
Ad fraud steals from advertisers by billing for fake impressions or clicks, often through bots or invalid traffic. Malvertising uses real impressions to attack the people who see them.
Typosquatting is the registration of misspelled domains to capture mistyped traffic. Malvertising campaigns often use lookalike domains as landing pages, but buying ads is not required for typosquatting, and the domain is not required for malvertising.
Adware is software already installed on a device that injects or displays ads. Malvertising can be the route by which adware is installed; it is not the software itself.
Recent developments
Regulators are moving from guidance to duties. In the UK, Ofcom opened a consultation on July 10, 2026, on draft Fraudulent Advertising Codes of Practice under the Online Safety Act 2023, with nearly 40 measures for large search and social services and an estimated GBP 200 million-plus lost by UK victims each year. Feedback closed on October 2, 2026. In Germany, the Frankfurt Regional Court ruled on September 16, 2026, that Meta's ad auction and ranking gave it enough control over content to lose its hosting exemption under the Digital Services Act in an impersonation case. The judgment is not final.
In the US, the Consumer Federation of America sued Meta over scam ads in the Superior Court of the District of Columbia in April 2026. TAG awarded 307 seals to 196 companies in its 2026 recertification, with its malvertising seal requiring creative scanning and incident reviews.
SourTrade illustrates where attacks are heading. "The browser is being used as the final assembly point," said Chris Olson, chief executive of The Media Trust, commenting on the campaign.
Timeline
- Late 2007 to early 2008: Ads exploiting an Adobe Flash vulnerability appear on MySpace, Excite and Rhapsody
- September 13, 2009: NYTimes.com warns readers about an unauthorised ad pushing fake antivirus software
- 2011: Spotify's client serves a malicious ad using the Blackhole exploit kit
- March 19, 2013: IAB unveils SafeFrame 1.0
- December 2013: Malicious ads reach Yahoo users
- February 2014: Malware is delivered through ads on YouTube
- May 14, 2014: US Senate Permanent Subcommittee on Investigations publishes its report on online advertising and consumer security
- September 30, 2014: The 4A's, ANA and IAB announce the Trustworthy Accountability Group
- March 2016: A RIG and Angler exploit-kit campaign reaches visitors of the BBC, The New York Times, MSN and AOL
- November 15, 2016: TAG launches its anti-malware certification
- July 31, 2017: TAG awards its first nine anti-malware seals
- January 2018: Confiant documents Zirconium's 1 billion impressions served in 2017; Chrome 64 blocks third-party iframe redirects
- April 2019: GeoEdge reports WebRTC-based malvertising in header bidding
- August 2019: Confiant reports a 0.25% malicious ad rate for the second quarter of 2019
- December 21, 2022: FBI warns of criminals impersonating brands through search ads
- October 18, 2023: Malwarebytes documents the KeePass Punycode search ad
- March 2024: Google begins immediate suspension for advertisers impersonating brands and public figures
- September 2024: GeoEdge detects the Morphixx revival targeting the UK and Germany
- November 6, 2025: Reuters reports Meta's internal scam ad revenue projections
- March 5, 2026: TAG announces 307 seals awarded to 196 companies
- April 16, 2026: Google publishes its 2025 Ads Safety Report
- April 21, 2026: Consumer Federation of America files suit against Meta over scam ads
- July 10, 2026: Ofcom opens consultation on Fraudulent Advertising Codes of Practice
- July 23, 2026: Confiant and Michael Steele document SourTrade
- September 16, 2026: Frankfurt Regional Court rules against Meta in the Finanzfluss impersonation case
Related PPC Land coverage
- SourTrade malvertising builds malware inside browsers, hits 12 countries - How a 2026 campaign assembled unique Windows executables inside victims' browsers.
- Malware hides in browsers as ad fraud outpaces detection - Weekly roundup with The Media Trust's Chris Olson on browser-assembled malware.
- Morphixx malvertising scam resurfaces with new tactics, targets UK and Germany - GeoEdge's 2024 findings on cloaking moved into the banner pre-loading stage.
- GeoEdge uncovers distribution of malvertising in Header Bidding - A 2019 WebRTC technique detectable only through behavioural analysis.
- Explaining Trustworthy Accountability Group - The history of TAG and its certification programmes, including anti-malware.
- TAG hands out 307 seals to 196 companies in 2026 recertification - The 2026 certification results and requirements of the malvertising seal.
- Chrome v64 to be released in January will block redirects on third party frames - The 2018 browser change that curbed forced redirects from ad iframes.
- Google cracks down on Impersonation tactics in Ads - The 2024 Misrepresentation policy update bringing immediate suspension for impersonators.
- Google's 2025 Ads Safety Report: Gemini blocked 8.3 billion bad ads - Google's 2025 enforcement figures by policy category.
- Google's 2023 Ads Safety Report shows progress in combating scams, deepfakes, and election misinformation - Enforcement totals for 2023 used as a baseline.
- Google suspended 38x more US ad accounts than TV had advertisers - VAB's reading of Google's figures and the ads that may have served before removal.
- Meta charged suspected fraudsters premium rates while earning billions from scam ads - Reuters' findings on Meta's scam ad revenue and penalty pricing.
- Consumer group sues Meta over scam ads that fund billions in revenue - The Consumer Federation of America's 2026 complaint in Washington, DC.
- Ofcom proposes scam-ad code as UK loses 200m a year to fraud ads - Draft UK codes imposing binding duties on paid advertising.
- Meta faces up to 250,000 euro fine per fake Finanzfluss ad after court loss - A German ruling that stripped Meta's hosting exemption for impersonation ads.
- Explaining invalid traffic - How non-human and fraudulent ad activity is classified and filtered.
Summary
Who. Criminal groups operate malvertising, often through front companies posing as advertisers or agencies. Ad networks, SSPs, DSPs, search engines and social platforms carry it unknowingly. Security vendors such as Confiant, GeoEdge, The Media Trust and Malwarebytes track it, and TAG, the FBI, Ofcom and courts set rules or issue warnings.
What. Malvertising is the use of paid online ads to deliver malware, forced redirects or phishing pages. Display variants hide code inside creatives and use cloaking to evade scanners; search variants impersonate brands to lure people to fake downloads and logins.
When. The first widely recorded cases appeared in late 2007 and early 2008. Exploit-kit attacks peaked between 2011 and 2016, forced redirects dominated from 2017, and brand impersonation through search ads surged from late 2022.
Where. It runs wherever ads run: news sites, apps, header bidding auctions, search results pages and social feeds, across every major market.
Why. Advertising offers cheap, targetable reach on trusted websites, and the number of intermediaries between buyer and screen makes vetting uneven. That combination lets attackers reach large audiences while showing reviewers something harmless.
Discussion