# What is Malvertising?

> Malvertising is the malicious use of online advertising to deliver malware, deceptive redirects, credential theft, fraud, or other harmful activity.

- Canonical URL: https://yellowcube.eu/glossary/malvertising/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

An attacker may buy apparently legitimate ad placement, submit a harmful creative, compromise an advertising account or supplier, or send selected viewers to an unsafe destination. The publisher, exchange, and other advertising participants are not necessarily complicit.

Digital ads can load content through several intermediaries and change by viewer, location, device, and time. Some campaigns require a click or further deception; others use redirects or exploit vulnerable browser components during page loading. This variability can make a report difficult to reproduce after the ad has rotated away.

### Key points

- **Delivery paths:** Harm may originate in ad code, a redirected landing page, a fake download or update, a browser notification prompt, or an exploit reached through the advertising chain.
- **Investigation:** Preserve the page address, time, screenshot, redirect chain, ad identifiers, browser and extension versions, downloaded files, and relevant endpoint and network telemetry without revisiting unsafe content.
- **Risk reduction:** Maintain browsers and extensions, limit unnecessary active content and notifications, use protective domain and web controls, isolate higher-risk browsing, and provide a clear reporting path for suspicious ads.
- **Important limitation:** Seeing an ad before an incident does not prove that the ad caused it, and blocking one domain or creative may not remove the campaign. Ad blockers and filtering reduce some exposure but cannot guarantee safe browsing or prevent every redirect and social-engineering path.

### Related terms

[Adware](<https://yellowcube.eu/glossary/adware/>) · [Malware](<https://yellowcube.eu/glossary/malware/>) · [Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Uniform Resource Locator (URL) filtering](<https://yellowcube.eu/glossary/uniform-resource-locator-filtering/>) · [Browser security](<https://yellowcube.eu/glossary/browser-security/>) · [Watering hole attack](<https://yellowcube.eu/glossary/watering-hole-attack/>) · [Drive-by compromise](<https://yellowcube.eu/glossary/drive-by-compromise/>)

### Sources

[CISA: Securing Web Browsers and Defending Against Malvertising for Non-Federal Organizations (August 2023 revision)](https://www.cisa.gov/sites/default/files/2023-09/Non-Fed%20-%20Guidance_for_Securing_Your_Web_Browsers%20Aug-23%20Revision.pdf) · [MITRE ATT&CK T1189: Drive-by Compromise](https://attack.mitre.org/techniques/T1189/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

