Malvertising, short for malicious advertising, is an attack that hides inside ordinary online ads. Criminals buy or hijack ad space on the networks that fill ad slots across much of the web. The ad looks like any other banner or video promo, but clicking it, and sometimes merely loading the page it sits on, starts an attempt to scam you or infect your device.
Malvertising does not stay in the shady corners of the internet. Malicious ads have appeared on major news, weather, and sports sites, because those sites sell ad space through automated auctions and never see most of what fills it. You can visit only well-known sites, click nothing suspicious, and still watch a fake virus alert take over your screen.
The good news is that the defense is mostly setup, not constant vigilance. A browser that updates itself, a good ad blocker, and a few habits decided in advance remove nearly all of the risk. This guide explains how the attacks work and exactly what to configure.
How malicious ads reach trustworthy sites
Most websites do not choose the ads you see. They hand a rectangle of space to an ad network, and the network fills it through an automated auction that completes in the instant the page loads. The winning bidder is usually a mattress brand. Sometimes it is a criminal with a stolen credit card and a convincing corporate front.
Attackers get past review in a few reliable ways. Some submit a clean ad, wait for approval, then quietly change where it points. Some take over the account of a small, legitimate advertiser and spend its good reputation. Others show a harmless version to reviewers and security scanners while serving the malicious version only to ordinary users, targeted by device type, region, and time of day.
A familiar address in the address bar therefore says nothing about the ads on the page: the site can be honest while the rectangle in its sidebar is not.
What a malicious ad can actually do
Malvertising is a delivery system, not a single scam. These are the payloads you are most likely to meet.
- Forced redirects. You tap an article and the page suddenly jumps to a spinning prize wheel, a gift card giveaway, or a survey scam. Code inside the ad triggered the jump, not anything you clicked.
- Scareware. A page announces that your device is infected, complete with a countdown timer, alarm sounds, and a logo borrowed from a real security company, all designed to panic you into installing junk software or paying for a fake cleanup.
- Tech support scams. Scareware with a phone number attached. The person who answers will ask for remote access, then charge you to fix problems that never existed. It runs on the same pressure tactics that make phishing work.
- Fake downloads and updates. A page claims your browser or a media player is out of date and offers a helpful button. The file behind it is a trojan. Real updates never arrive through an ad.
- Notification hijacking. The ad tricks you into clicking Allow on a browser notification prompt. Scam alerts styled to look like system warnings then arrive on your desktop or phone, even with the site long closed.
- Drive-by downloads. The most severe and now the rarest form, where simply loading a booby-trapped ad exploits an unpatched browser to install malware with no click at all. Automatic browser updates have mostly shut this down, which is why staying current matters more than any other habit.
Whatever lands, spyware, a trojan, or ransomware, behaves like any other infection once running. Our guide to the main types of malware explains what each one does and how removal works.
Where you are most likely to run into it
Any page with automated ads can carry a bad one, but the risk is not evenly spread.
- Sponsored search results. Criminals buy ads against searches for popular free software, then serve a pixel-perfect copy of the official site with a poisoned installer. When you need a program, skip the sponsored links and type the developer's address yourself.
- Free streaming and file-sharing sites. Unlicensed sports streams, torrent indexes, and file hosts run the most aggressive ad networks. Fake play buttons, layered popups, and forced redirects are the norm there.
- In-app ads on phones. Free games and utility apps use the same networks. A full-screen ad that opens your browser or the app store on its own is the mobile forced redirect.
Malvertising is not the same as adware
Both involve unwanted ads, but they live in different places. Adware is a program already installed on your device, usually bundled with a free download, that injects extra ads into pages and pops them up on your desktop. Malvertising comes from outside, through the ad slots of sites you visit, and leaves when the page does.
The distinction tells you what to do. Ads appearing where ads should not be, on your desktop or over every website, mean something is installed: run a full antivirus scan. A hostile ad on an otherwise normal site means your device is probably fine.
Warning signs an ad is attacking you
Hostile ads announce themselves once you know the tells.
- Countdown timers, alarms, and a hijacked screen. A page that shows a ticking deadline, plays siren sounds, or hides your browser controls is a scam page, full stop. Timers exist to stop you from thinking.
- Infection claims from a web page. A website cannot scan your device. Any ad that lists viruses it supposedly found is inventing them.
- Update prompts inside the page. Browsers and operating systems update through their own settings screens, never through a banner.
- A phone number to call. Real security warnings do not come with a support line. That number reaches the scammer's call center.
One rule covers all of these: real warnings do not come from web pages. Your antivirus does not run in a browser tab, and your operating system does not speak to you through an ad slot.
The setup that makes malicious ads a non-event
Each step removes a whole category of attack, and none needs repeating daily.
- Let your browser update itself, and restart it regularly. Most browsers download updates automatically but only apply them after a restart. If the menu button shows a colored dot or an update label, restart now.
- Install a reputable ad blocker. Blocking ads removes the delivery vehicle itself: an ad that never loads cannot redirect or scare you. Get one from your browser's official extension store, then confirm it is working with our free ad blocker test.
- Update through your device, never through a page. On an iPhone, that is Settings, then General, then Software Update. On Windows, it is Settings, then Windows Update. Anything else asking you to update is lying.
- Clear your notification permissions. In your browser's settings, search for notifications and remove every site you do not recognize from the allowed list. This silences fake system warnings planted by earlier scam pages.
- Keep real-time antivirus protection on. On Windows, the built-in Windows Security app is a solid baseline that checks downloads as they arrive, so a poisoned installer gets caught before it runs. On a phone, stick to the official app store.
- Trim your extensions. Remove browser extensions you no longer use. Abandoned ones are sometimes sold off and updated into adware, turning your own browser into the ad injector.
If you clicked, or something already ran
Move calmly through these steps. Speed helps, panic does not.
- Close the tab. If the page hides the close button or a dialog keeps reappearing, close the whole browser: on Windows, press Ctrl+Shift+Esc, select the browser in Task Manager, and choose End task. On a Mac, press Option+Command+Esc and force quit. When you reopen, decline any offer to restore your tabs.
- Do not call the number, and never grant remote access. If someone is already connected to your machine, disconnect from the internet, uninstall the remote access program they had you install, and run a full scan.
- Downloaded a file? Delete it unopened, then empty the trash so it cannot be launched by accident later.
- Opened the file? Turn off Wi-Fi, then run a full scan. On Windows, open Windows Security, choose Virus & threat protection, then Scan options, then Full scan.
- Typed a password on a page an ad led you to? Change it from a device you trust, then turn on two-factor authentication for that account.
- Entered card details? Call your bank or card issuer, ask them to block and reissue the card, and watch your statement for small test charges.
A five-minute hardening session
Do these now, in order. Together they neutralize nearly every malicious ad you will ever load.
- Restart your browser so any waiting update applies, then confirm automatic updates are on in its settings.
- Install an ad blocker from your browser's official extension store and verify it is actually blocking.
- Open your browser's notification settings and remove every site you do not recognize.
- Check that your phone and computer install system updates automatically.
- Commit to two rules while nothing is flashing at you: never call a number that appears in a warning page, and never install anything a web page tells you to install.