166 terms · 75/46/45
Threat № 032 · class: social eng.

Malvertising

Malvertising uses ad networks as a delivery channel for attacks. The user does not have to be on a dubious site; a malicious advert can appear on a legitimate portal too, because ad space often arrives through several intermediaries.

Term

description · examples · notes

Malvertising uses ad networks as a delivery channel for attacks. The user does not have to be on a dubious site; a malicious advert can appear on a legitimate portal too, because ad space often arrives through several intermediaries.

Description

The attack may require a click, but not always. Sometimes the advert leads to a fake page for a browser update, a program download or a credential entry. In worse cases a vulnerable browser or extension can be exploited by the content simply loading.

The problem is the trust the user carries over from the site to the advert. If the portal is well known, the advert seems more harmless. The site owner often does not know that harmful content is being shown through their space, and the user sees only the end result: an advert taking them somewhere they should not go.

Examples

  • An advert on a well-known news portal redirects the user to a page offering a fake browser update.
  • A paid search advert leads to a fake site for popular software, where a Trojan is downloaded instead of the legitimate installer.
  • A banner loads code that exploits a vulnerability in an old browser or extension, with no clear interaction from the user.

Notes

  • A familiar site is no guarantee that every advert on it is safe.
  • An up-to-date browser, blocking suspicious adverts and web filtering are not comfort here but a reduction of the attack surface.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 3

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 5

How it is defended against. Select one to open its page.