What is malvertising?
Malvertising is the use of online ads to deliver malware, scams or forced redirects. Criminals buy ad space or compromise ad creatives so that simply viewing or clicking an ad sends users to phishing pages, fake tech-support scams or malicious downloads. It harms users and publishers even on legitimate, reputable websites, because the bad ad arrives through normal ad channels.
Malvertising slips in through the programmatic pipes: a bad actor passes review with a clean creative, then switches behavior after approval, or uses cloaking so scanners see a harmless page while real users are redirected. Mobile users often experience it as sudden redirects to "you won a prize" pages or fake app-store prompts.
Publishers fight it with creative scanning and blocking tools, strict SSP creative policies and sandboxing ad iframes. Advertisers are rarely the source, but the industry's TAG and platform policies require buyers and sellers to vet demand partners. Users can reduce risk with updated browsers and caution around ads promising prizes or urgent security warnings.