Malvertising
In plain terms
A booby-trapped ad displayed on a perfectly legitimate site. The site did nothing wrong: it rents out a slot, and what shows up in it is decided elsewhere, in a fraction of a second.
Definition
Malvertising is the distribution of malicious content through advertising networks, which lets it be displayed on legitimate sites without those sites being compromised.
How it works
A site's ad space is sold automatically, ad by ad, on every page load. What you see was therefore not chosen by the site you're visiting, and it never even saw it. The attacker buys that space like any other advertiser, which gives them the host site's reputation without having had to hack it. Two uses dominate. The first hijacks search: an ad bought on the name of a well-known piece of software appears above the official result, and the download offered isn't the publisher's. The second triggers a redirect or a fake alert as soon as the page loads, with no click required.
Warning signs
- Sponsored result placed above the official site for the name of a piece of software
- Redirect triggered without a click, when an ordinary page loads
- Fake security or update alert popping up on an unrelated site
- Ad domain different from that of the advertised publisher
- Download offered from a download site rather than from the publisher
How to verify
Ignore blocks flagged as advertising or sponsored in search results, and scroll down to the organic result. For a piece of software, type the publisher's address rather than searching for its name: the search itself is the battleground for this attack, and bypassing it removes the problem.
What to do
Download from the publisher's site or an official app store, never from a sponsored link. An ad blocker significantly reduces exposure, and keeping the browser up to date closes off the redirects that require no click at all.
If it already happened
If a file was downloaded and run, disconnect the device from the network and have it scanned, then change your passwords from another healthy device starting with email. If you only logged in on a page reached through an ad, change that password and revoke sessions.
Frequently asked questions
- The site I was on is a big, well-known site.
- That doesn't change anything, and it's the whole point of the attack: the ad wasn't chosen by that site. Its slot is sold automatically on every display, and its seriousness says nothing about the content passing through it.
- Is an ad blocker enough?
- It significantly reduces exposure and is a useful measure, but it doesn't cover search engines' sponsored results or content embedded another way. The habit that's still needed is reaching a publisher by its address rather than through a search.
Related attacks
Official sources
This article is part of the Website and browser attacks family. Last updated: 2026-09-02.