Malvertising
Also known as: Malicious advertising, Malicious ads, Ad-network malware delivery, Rogue ad redirect
Criminals buy or inject ads on legitimate networks so that a trusted site ends up serving visitors a scam redirect or a malware delivery path without the site itself being hacked.
How it works
Malvertising is the abuse of online advertising to deliver malware or scams. The attacker does not break into the publisher. They buy ad space, or compromise an advertiser or ad-tech account, and place a harmful creative that the ad network then serves to ordinary visitors of ordinary sites.
A typical ad is not one file. It is a chain: the page loads a script from an ad network, which calls an exchange, which pulls a creative from an advertiser. Any link can be replaced or abused, so the publisher is trusting parties it has never met, and a harmful creative can appear for some visitors only, which makes it hard to reproduce.
The harm usually shows up in one of two ways. Some ads redirect the visitor away to a fake alert, scam page or lure to install something. Others try to reach vulnerable browser components so that merely visiting the page is enough, which maps to drive-by compromise. Patched, hardened endpoints blunt the second kind.
Defence has two sides. Publishers vet and limit ad partners, constrain what ad content may load with a content security policy and framing restrictions, and keep third-party script to a minimum. Endpoints add ad and script blocking, prompt patching, browser hardening and EDR. Analysts connect visitor reports to the responsible ad domain and act on it.
Walk through it
- 1Visitors report odd redirects
- 2Trace it to an ad domain
- 3What does your page allow?
- Scope exposed visitors and endpoints
- Contain and harden the ad chain
Support has forwarded several complaints from readers of your own site. Nothing on your servers changed, yet readers say the page sends them elsewhere. Read the ticket carefully before you assume your site was breached.
Readers report fake virus alerts on article pages
Seven reports in two hours. Readers say a full-screen warning about a computer virus appears, or they are sent to a prize page.
It happens on article pages only, on both phones and laptops, and not every time.
Web hosting shows no deploys, no admin logins and no file changes today.
Ad operations confirms the article template loads banners from a third-party ad network.
Spot it
- Several visitor or support reports of fake alerts, prize pages or unexpected redirects from content pages without any deploy.
- Top-level navigations initiated by third-party ad or creative hosts rather than by first-party page code.
- Requests to ad-related hosts that are not in the ad partner contract list, or to newly registered domains.
- Endpoint alerts shortly after a visit to the site, such as a browser spawning an unexpected process or a new download.
- Problems that appear only for some visitors, devices or regions, which matches targeted ad serving.
Browser telemetry
ts=2026-10-11T10:02:13Z page=/news/storm-season request=https://cdn.fastclicks-media.example/creative/88213.html party=third approved=false
ts=2026-10-11T10:02:14Z page=/news/storm-season event=top_level_navigation initiator=cdn.fastclicks-media.example target=prize-claim-hub.exampleWeb proxy
ts=2026-10-11T10:02:14Z user=j.okoye src=WS-0412 method=GET host=prize-claim-hub.example category=newly_registered referrer=cdn.fastclicks-media.example action=allowedkqlThird-party hosts initiating top-level redirects
BrowserTelemetry
| where EventType == "top_level_navigation" and InitiatorParty == "third"
| summarize Hits=count(), Pages=dcount(Page) by InitiatorHost
| order by Hits descCheck hits against the ad partner list. Some legitimate ad flows navigate on a click, so look at navigations with no user interaction.
splProxy visits to newly registered hosts referred by ad domains
index=proxy category=newly_registered referrer_host IN ("*fastclicks-media*", "*brightbanner*")
| stats count, dc(user) as users by host, referrer_hostStop it
Constrain what ad content may load
Publish a content security policy that names the contracted ad hosts for frames and scripts, and drop wildcard sources. The browser then refuses a creative from an unknown host even when the ad network itself was tricked.
Vet partners and keep third-party code small
Work only with ad networks that offer contractual security terms, creative scanning and a fast takedown route. Load as few third-party scripts as the business needs, and pin them with Subresource Integrity where the provider supports fixed files.
Harden endpoints and monitor
Keep browsers and plug-ins patched, use ad and script blocking on managed devices, and keep EDR active so a drive-by attempt is stopped or alerted. Monitor for third-party redirects to catch a campaign early.
Policy intent: frame only contracted ad hosts, no wildcard scripts
Vulnerable
Content-Security-Policy: default-src * ; script-src * 'unsafe-inline'Hardened
Content-Security-Policy: default-src 'self' ; frame-src https://adserve.brightbanner.example ; script-src 'self' https://adserve.brightbanner.example ; report-to csp-endpointStart in report-only mode to find legitimate ad dependencies. Sandbox ad iframes with the sandbox attribute where the ad provider allows it.
- Replace wildcard CSP sources with an explicit list of contracted ad and script hosts, and collect violation reports.
- Use the iframe sandbox attribute for ad slots and restrict top-level navigation from ad frames where compatible.
- Limit third-party JavaScript on high-value pages and review the ad partner list on a schedule.
- Keep operating systems, browsers and plug-ins patched on managed endpoints.
- Deploy ad and script blocking and keep EDR running on user devices.
If it already happened
Ask the ad network to pause the offending creative or advertiser, block the creative host and the landing domain at DNS and proxy, and temporarily disable the affected ad slots if reports continue.
Identify visitors and managed devices that loaded the creative, scan those endpoints for new downloads or processes, and remove anything found. Report the creative to the ad network and the domain registrar.
Re-enable ad slots only once the network confirms the creative is removed and your policy is enforcing the contracted host list. Communicate to readers if their devices may have been affected.
Tighten the CSP, review the ad partner contract for scanning and takedown terms, and add detections for third-party redirects.
Check yourself
1. A news site is not breached, yet readers are redirected to scam pages. What is the most likely cause?
2. Which publisher-side control best limits which hosts may be loaded as frames or scripts on a page?
3. Which endpoint measure most directly reduces the chance a visit to an ad-carrying page leads to compromise?