Attack technique

Malvertising

Malicious code delivered through legitimate online advertising networks, so that even a trusted, high-traffic website can unknowingly serve a compromised ad that installs malware or redirects visitors to a fake page.

Definition

Malvertising is the distribution of malicious code through legitimate online advertising networks, meaning the website displaying the ad has not itself been hacked, only the ad served on it is compromised. Because programmatic ad networks place ads dynamically across huge numbers of publishers, a single malicious campaign can appear on trusted, high-traffic websites, exposing visitors to malware installation or redirection to a fake page without them clicking on anything unusual or visiting an unfamiliar site.

Attackers typically buy legitimate-looking ad space through a real ad exchange, sometimes submitting a clean, innocuous creative that passes initial review and then swapping in malicious code afterward, or compromising an existing advertiser's account to inject a malicious ad into an already-approved campaign. The malicious ad may trigger a silent, drive-by redirect simply by loading on the page, no click required, or it may lure a click into an exploit kit or a convincing fake software update page. Because the ad network distributes the campaign across countless publishers and intermediaries automatically, a single malicious buy can reach a large audience quickly and is often difficult to trace back to its original source.

This makes malvertising dangerous precisely because it turns routine, trusted browsing into a risk: employees reading a familiar news site, an industry forum, or a well-known service during a normal workday are exposed without opening a single suspicious email or clicking an unfamiliar link. The resulting infections range from ransomware and other malware to fake update pages designed for credential harvesting, and because the campaigns are served through legitimate advertising infrastructure, neither the employee nor the publisher necessarily has any reason for suspicion until something goes wrong.

Reducing exposure combines patched software with browser-level and network-level controls: keeping browsers, plugins, and operating systems updated closes the known exploits many malvertising campaigns rely on, reputable ad-blocking or browser isolation tools on corporate devices prevent most malicious ads from loading at all, and network-level web filtering can block known malicious ad domains. Employees should be trained to never act on an unexpected 'update now' prompt triggered by an ad, updating software only through official channels instead, and to report unexpected pop-ups, redirects, or forced downloads immediately rather than dismissing them as routine browser quirks.

At a glance

Severity
Medium-High
Prevalence
Common
Primary targets
Any visitor to high-traffic websites carrying ads served through a compromised or malicious ad campaign

How it works

  1. 1

    Ad placement: the attacker buys legitimate-looking ad space through a real ad exchange, or compromises an existing advertiser's account.

  2. 2

    Payload swap: after passing initial review, the ad is altered to include malicious code, or set to trigger only under certain conditions to evade detection.

  3. 3

    Distribution: the ad network serves the malicious ad automatically across many legitimate, high-traffic websites unrelated to the attacker.

  4. 4

    Trigger: simply loading the page can silently redirect the visitor in a drive-by attack, or a click leads to an exploit kit or a fake software update page.

  5. 5

    Infection or harvest: the visitor's device is infected with malware, or they are tricked into entering credentials on a fake page.

Warning signs

  • Unexpected pop-ups, redirects, or 'update now' prompts while browsing an otherwise normal website
  • A download starting without you clicking anything
  • Ads that look unusually alarming, such as fake virus warnings or urgent software update notices
  • Browser or antivirus warnings appearing immediately after visiting a familiar site
  • Unusual device slowdown or new toolbars and extensions appearing after ordinary browsing

How to defend

  • Keep browsers, plugins, and operating systems fully patched, since malvertising often relies on known exploits
  • Use a reputable ad blocker or browser isolation tool on corporate devices
  • Never click an 'update now' prompt triggered by an ad; update software only through official channels
  • Run endpoint protection that can detect and block drive-by downloads
  • Report unexpected pop-ups, redirects, or forced downloads immediately rather than dismissing them
  • Apply network-level web filtering to block known malicious ad domains

Real-world example

An employee at an Indonesian insurance company reads a trusted local news site during her lunch break. An ad on the page silently redirects her browser to a message claiming her media player is out of date. Instead of clicking install, she recognizes the fake update prompt from her security training, closes the tab, and reports it to IT rather than downloading the file.

How Claro helps

Claro's awareness training extends the same stop-and-verify instinct built for suspicious emails to unexpected pop-ups, ads, and 'update now' prompts encountered while browsing, and reported incidents, including malvertising-triggered downloads, feed into the same risk-scoring and reporting workflow security teams already use for reported phishing.

Frequently asked questions

What is Malvertising?

Malvertising is the use of online advertisements to spread malware or direct victims to malicious sites, sometimes infecting a device even without a click through the ad network.

How is malvertising different from a compromised website?

A compromised website, as in a watering hole attack, is itself hacked to serve malicious content directly. Malvertising instead abuses the legitimate ad network serving a site, so the website itself is not hacked, only an ad displayed on it is malicious.

Can malvertising infect me without clicking anything?

Yes. In a drive-by variant, simply loading a page containing the malicious ad can trigger a silent redirect or exploit attempt with no click required at all.

Do ad blockers stop malvertising?

Reputable ad blockers prevent most malicious ads from loading at all, making them one of the most effective defenses, though they are not a complete substitute for patched software and endpoint protection.

Why is malvertising hard to trace back to a source?

Programmatic ad networks distribute campaigns dynamically across countless publishers and intermediaries, so a malicious campaign can appear on many unrelated legitimate sites and be pulled quickly, making the original attacker difficult to identify.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo