Malvertising explained: when the ad supply chain becomes an attack vector
Malvertising uses legitimate ad networks to deliver malware, scams, and forced redirects to real users on real sites. Here's how it works, why the supply chain makes it possible, and how publishers and buyers defend against it.
Most ad-quality conversations are about money — fraud stealing budget, MFA wasting it. Malvertising is different, and worse: the victim isn’t the advertiser’s budget, it’s the user. It weaponizes the ad supply chain to deliver malware, scams, and hijacked browsing sessions to real people on legitimate sites — which makes it a security problem and a trust problem, not just a quality one.
Here’s how malvertising works and how to defend against it.
What malvertising is
Malvertising (malicious advertising) is the use of legitimate advertising infrastructure to distribute malicious content. An attacker buys ad inventory like any advertiser, but the creative — or the code inside it — is designed to harm the user.
The critical and counter-intuitive point: the publisher is a victim, not the culprit. A trusted, well-run site can serve a malicious ad without any compromise of its own systems, because the ad arrived through the same programmatic pipes as everything else. The attacker rented the distribution.
What it actually does
Common payloads:
- Forced redirects. The most frequently encountered form — the ad hijacks the browser and throws the user onto a scam page (“your device is infected,” fake prize pages) without any click.
- Scams and phishing. Fake support numbers, fraudulent offers, credential-harvesting pages, crypto scams.
- Malware delivery. Drive-by downloads or exploit kits that attempt to install software, historically without any user interaction.
- Cryptojacking. Scripts hijacking the visitor’s CPU to mine cryptocurrency while the ad is on screen.
Why the supply chain makes it possible
Malvertising exploits structural features of programmatic:
- Scale and automation. Millions of creatives flow through automatically; nothing human reviews each one.
- Long, opaque supply chains. The more intermediaries and resold hops between buyer and publisher, the more places a bad creative can enter and the harder it is to trace after the fact.
- Creative is code. Modern ads execute JavaScript in the user’s browser, so a creative isn’t a picture — it’s a program running on the page.
- Cloaking and evasion. Attackers show benign creative to scanners and malicious behaviour to real users, or trigger the payload only for specific geographies, devices, or times — so a creative that passed review misbehaves in the wild.
- Low barriers to buying. Anyone with a card can become a “buyer,” and weak vetting at the entry point lets attackers in.
A malicious ad isn’t a hacked website — it’s a rented one. The attacker didn’t break into the publisher; they bought their way in through the same door as every other advertiser.
How it’s defended against
Defense is layered, and mirrors the broader quality playbook:
- Creative scanning and sandboxing. Vendors execute creatives in controlled environments to detect redirects and malicious behaviour — necessary, but defeated by cloaking that detects the sandbox.
- Real-user monitoring. Because cloaking beats scanners, detecting behaviour as experienced by actual users is essential.
- Buyer vetting and payment diligence. Making it harder and costlier to become an anonymous buyer removes a lot of low-effort attackers.
- Supply path discipline. Fewer hops, verified sellers, and clean paths shrink the surface where a malicious creative can enter and make tracing possible.
- Blocking risky creative behaviours — automatic redirects and certain scripting patterns — at the ad-serving layer.
- Fast takedown. Because attacks are bursty, the time from detection to removal matters more than perfect prevention.
Why publishers should care most
The revenue lost to a malicious campaign is trivial next to the damage: users who get redirected to a scam blame your site, not an anonymous intermediary. That erodes trust, drives ad blocker installs, and can lead to browser or security warnings on your domain. Malvertising is one of the strongest arguments for treating supply and demand quality as a first-class concern rather than a compliance checkbox.
The takeaway
Malvertising abuses legitimate ad infrastructure to deliver forced redirects, scams, and malware to real users on real sites — with the publisher as victim rather than culprit. It thrives on automation, long opaque supply chains, executable creative, and cloaking that fools scanners. Defense means layering creative scanning with real-user monitoring, vetting who’s allowed to buy, shortening and verifying supply paths, and moving fast on takedowns. Unlike most ad-quality problems, the cost here is measured in user trust — which is far harder to win back than budget.
Lumorrow evaluates supply provenance and quality in real time, pre-auction — shortening the path and shrinking the surface where malicious inventory can enter. See how the platform works →.