What is malicious advertising?¶
Malicious advertising, or malvertising, uses or abuses online advertising to redirect, deceive or deliver malicious content. The website displaying an advert may have no knowledge of it because delivery often passes through several platforms and exchanges.
An advert may imitate a brand, show a fake warning, promote a fraudulent download, redirect to phishing or attempt browser exploitation.
Preserve the delivery chain¶
Record the page, advert appearance, timestamp, browser and device, but also capture the advert or campaign identifiers, click and redirect sequence, final destination and related security events. A screenshot alone cannot show which provider supplied the content or what happened after interaction.
Advertising can be targeted by geography, device, time and profile, then changed or withdrawn quickly. Provider logs, browser records and network data may therefore be more reliable than trying to reproduce the advert later.
Separate display from compromise¶
An advert can be displayed without being clicked, a redirect can occur without the destination loading, and a protection control can block content before execution. Establish each stage and the resulting device or account activity.
Likewise, a malicious campaign identifier or advertiser account does not automatically identify an offender. Accounts and infrastructure may be compromised or registered with false information. Preserve blocking evidence explicitly: it can prove attempted delivery while supporting the narrower conclusion that a harmful component did not reach the device.
Key takeaway
Preserve the advert and its changing provider-to-destination route, then distinguish display, interaction, redirection, blocking and compromise.