← All terms

Malvertising

Malvertising is the use of online advertising to spread malware or lead users to phishing pages, often through legitimate ad networks and search ads.

Malvertising — malicious advertising — abuses legitimate online ad networks to deliver malware or drive victims to phishing pages. Because the ads run on trusted websites and in search engine results, malvertising reaches victims who never clicked a suspicious email or mistyped a URL: the attack comes to them through the normal machinery of the web.

How it works

Attackers either compromise an existing advertiser account or pose as a legitimate advertiser, then submit ads that pass the network's review. The malicious behavior is often cloaked — the ad serves clean content to reviewers and scanners, and the payload only to real victims matching the targeting criteria. Common patterns include:

  • Search ad impersonation. The attacker buys search ads for popular software ("download Zoom", "AnyDesk", "KeePass") or brand names. The ad links to a near-perfect clone of the vendor's site — often on a typosquatted domain — serving a trojanized installer. Because paid results appear above organic ones, even careful users land on the fake first.
  • Drive-by redirects. A malicious ad on a legitimate news or entertainment site silently redirects the browser to an exploit kit or a fake update page ("your browser is out of date").
  • Fake alerts. Ads that render as system warnings funnel victims into scareware flows and fraudulent support call centers.

For corporate targets, the search-ad variant is the most consequential: it is how employees looking for IT tools end up installing loaders and infostealers, whose harvested credentials later feed account takeover and MFA fatigue attacks. Its logic resembles a watering hole attack — compromise the place the victim already visits — but rented rather than hacked.

How to defend against it

  • Route software installs through an internal catalog or managed app store, so employees never need to search for installers.
  • Deploy DNS and web filtering that blocks newly registered and known-malicious domains, and consider ad-blocking on managed browsers.
  • Teach the paid-result habit: scroll past ads to organic results when downloading software, and verify the domain before installing anything.
  • Include fake-download lures in awareness programs. Simulations built around "install this update" scenarios in security awareness training translate this abstract threat into a recognizable moment.

Related terms

Watering Hole AttackA watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.TyposquattingTyposquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo