09.12.26

What is malvertising? How dangerous ads can infect or redirect your device

Online ads can help you discover products, services, and useful information. Unfortunately, some advertisements hide a more dangerous purpose.

Malvertising, short for malicious advertising, uses compromised or deceptive online ads to distribute malware, redirect people to fraudulent websites, or steal sensitive information. These ads may appear on questionable sites, legitimate websites, social media platforms, and even search results.

What is malvertising and how does it work?

The Cybersecurity and Infrastructure Security Agency’s malvertising guidance defines malvertising as the use of malicious or hijacked advertisements to spread malware. Criminals may insert harmful ads into legitimate advertising networks, allowing the ads to appear on websites that have no idea they are serving dangerous content.

A malicious ad can attack in several ways:

  • Redirect you to a fake login, shopping, or tech support scam page
  • Promote a fraudulent software download
  • Display a fake virus or browser-update warning
  • Send you through several websites before reaching a malware download
  • Exploit an unpatched browser vulnerability
  • Trick you into copying and running a malicious command

Some attacks require a click. Others may use hidden scripts or unpatched vulnerabilities to deliver a harmful payload when the advertisement loads. CISA specifically warns that certain malvertising can compromise a network even if the user does not click the ad.

How dangerous is malvertising?

Malvertising can affect consumers at scale. In March 2025, Microsoft Threat Intelligence reported that one large malvertising campaign affected nearly one million devices worldwide. The campaign started on illegal streaming websites and redirected users through intermediary sites to malicious files hosted on several platforms.

Microsoft found that the campaign used multiple stages to collect system information, deploy more malicious files, and steal documents and data. It affected both consumer and enterprise devices across multiple industries.

That scale shows why an online ad should not automatically earn your trust just because it looks professional or appears on a familiar website.

Can malvertising infect a device without a click?

Yes, under some circumstances. CISA says malicious ads can run hidden scripts, force redirects, or interact directly with users. Unsecure configurations and outdated browsers increase the opportunity for attackers to exploit a device. [

However, not every malicious advertisement automatically causes an infection. The outcome depends on factors that include the ad’s design, the website, browser protections, software vulnerabilities, and whether the user follows additional instructions.

Modern attacks also combine malvertising with social engineering. Microsoft’s analysis of the ClickFix technique describes campaigns that use malvertising and fake verification prompts to persuade people to copy, paste, and run malicious commands themselves.

What does a malicious ad look like?

Malvertising often imitates something familiar or urgent. Watch for ads that:

  • Claim your device has a virus
  • Demand an immediate browser or software update
  • Offer expensive software or subscriptions for free
  • Impersonate a known retailer, antivirus company, or technology brand
  • Place a “Download” button beside unrelated content
  • Ask you to disable security software
  • Instruct you to open PowerShell, Terminal, or the Windows Run dialog
  • Redirect you repeatedly or open unexpected tabs
  • Request passwords, card numbers, or cryptocurrency payments

The Federal Trade Commission advises consumers to be cautious of appealing websites and desirable downloads that lead to malware. The FTC also notes that spyware may redirect computers, monitor browsing, or record keystrokes.

How can you protect yourself from malvertising?

Keep browsers and devices updated

Install browser, operating-system, and security updates promptly. CISA identifies outdated browsers and insecure configurations as common weaknesses associated with malvertising. [cisa.gov]

Avoid sponsored links for sensitive tasks

When downloading software or signing in to a financial account, type the known website address yourself or use a trusted bookmark. Do not assume a sponsored result is the official website.

Use reputable security protections

Enable built-in browser protections and use reputable anti-malware software. CISA also recommends advertising-blocking controls and protective DNS technologies as potential organizational defenses against malicious advertising.

Treat fake updates as a warning sign

Close the page if an advertisement says you must install an urgent browser update. Use your browser’s built-in update menu or visit the developer’s official website instead.

Never run commands supplied by a webpage

A legitimate CAPTCHA or verification check should not require you to paste commands into PowerShell, Terminal, or a Run box. Microsoft says ClickFix campaigns exploit seemingly harmless verification and troubleshooting prompts to persuade victims to execute malicious instructions.

What should you do after clicking a suspicious ad?

If you clicked but entered nothing:

  1. Close the page and unexpected tabs.
  2. Do not accept notifications or download files.
  3. Update your browser and operating system.
  4. Run a full security scan.
  5. Review recently installed apps and browser extensions.

If you downloaded or ran something:

  • Disconnect the device from the internet.
  • Run an updated anti-malware scan.
  • Change important passwords from a clean device.
  • Enable multifactor authentication.
  • Check banking, email, and shopping accounts.
  • Report deceptive advertisements through the platform where they appeared.
  • Report scams through the FTC’s official fraud-reporting service.

How does this help someone become safer online?

Understanding malvertising changes a risky habit: trusting an advertisement because a search engine, website, or social network displayed it.

When you verify destinations independently, keep software patched, reject fake updates, and avoid webpage-supplied commands, you reduce opportunities for attackers to:

  • Install information-stealing malware
  • Capture passwords and payment information
  • Redirect you to impersonation sites
  • Gain remote access to your device
  • Use one compromised account to attack others

Malvertising turns ordinary online advertising into a delivery channel for redirects, scams, and malware. A polished ad is not proof of safety, and a familiar website cannot guarantee that every third-party advertisement is trustworthy.

Pause before clicking sponsored results. Visit official websites directly, keep your browser updated, and treat unexpected downloads or technical instructions as warning signs. These small habits make digital advertising much less useful to cybercriminals.