The destination may be a site the attacker controls, a compromised legitimate site, or content injected through advertising or third-party resources. Delivery can be indiscriminate or restricted to selected visitors by geography, device, or other profile characteristics.
Classic cases exploit unpatched browsers, plug-ins, or rendering components during page load. Other flows rely on deception — a fake update, a disguised installer prompt, or a permission request that leads the visitor to run something voluntarily. The distinguishing feature is that browsing itself is the attack path.
Key points
Delivery pathsExploit of browser or component weaknesses, malicious or hijacked page content, compromised third-party resources, deceptive downloads, and permission or notification prompts.
InvestigationPreserve the page address, time, redirect chain, browser and extension versions, downloaded artifacts, and endpoint and network telemetry without revisiting the content.
Risk reductionMaintain browsers and related components, govern extensions, apply web filtering and isolation where justified, monitor for post-visit execution, and give users a way to report suspicious pages.
Important limitationA page visit preceding an infection does not prove the page caused it, and content that targeted only some visitors may be unrecoverable afterward. Blocking a single domain rarely ends a campaign that can rotate infrastructure.