Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain
Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain
Read Time:4 Minute, 24 Second

Malicious advertising is undergoing a structural shift that is making it significantly harder to catch with traditional review methods. Rather than relying on an obviously deceptive ad or landing page, a growing share of malvertising campaigns now hide their malicious behavior several steps downstream — inside redirect chains, disposable domains, cloaking systems, and delivery logic that can change after a campaign has already been approved.

What the Numbers Show

Analysis of ad-network moderation data covering the first half of 2026 illustrates the trend clearly. Rejections tied to malware and antivirus-flagged threats actually rose in absolute terms — from roughly 8,400 in the first quarter to about 9,500 in the second — even as total campaign rejections overall fell sharply, dropping 42% over the same period. As a share of all rejected campaigns, malware and threat-related takedowns jumped from roughly 23% to nearly 46%, making them the single largest rejection category. Much of that shift in proportion reflects adult-content violations being filtered out earlier and more efficiently in the moderation pipeline, but the underlying point stands: technical, harder-to-detect threats kept growing even as easy, obvious violations became easier to catch and stop.

The pattern isn’t isolated to one dataset. Separate industry research has found redirect-based malvertising attacks climbing from 48% to 66% of malicious ad activity year-over-year, with overall malicious ad activity doubling across the largest markets tracked. Other telemetry has found malvertising accounting for close to 30% of all threat detections in a major browser’s consumer security data, underscoring just how mainstream this delivery method has become. Cloaking — deliberately hiding a campaign’s true destination or behavior from reviewers — remained remarkably consistent as a tactic, showing up in roughly two-thirds of advertiser suspensions across both quarters studied.

The Malicious Asset Is the Chain, Not the Page

Traditional ad review focuses on what’s directly visible: the creative, the landing page, the offer, and any domains obviously tied to them. That approach breaks down when the actual malicious behavior is spread across several distinct technical components instead of sitting in one place.

A typical campaign now might start with a compliant-looking ad and an entirely clean landing page, then route the visitor through a series of tracking services, intermediate domains, and conditional redirects before ever reaching the true destination. Each individual hop can appear harmless in isolation; the risk only becomes visible once the entire path is reconstructed end to end. One industry report describes malicious creatives increasingly built to activate “only under particular geographic, device, or behavioral conditions” — meaning a single, one-time check performed at approval time tells reviewers very little about what real users will eventually see.

This layered architecture gives attackers several practical advantages: it separates the original approved ad from the eventual payload, lets individual domains be swapped out without rebuilding the whole campaign, and allows traffic to be segmented so that different visitors — based on geography, device type, or other signals — are routed to entirely different outcomes.

A Real-World Example

Researchers at Confiant documented a campaign active since late 2024 that impersonated well-known brands, including TradingView, Solana, and Luno, across 12 countries and 25 languages. Its landing pages actively fingerprinted incoming visitors: anyone who looked like a security researcher or automated scanner was served a blank, harmless page, while genuine targets were shown convincing replicas of the impersonated services. That kind of selective delivery makes the campaign effectively invisible to anyone reviewing it from the “wrong” vantage point — which, historically, has included most automated security scanners.

Market Economics Shape the Threat

The data also suggests that where a campaign runs shapes how it’s built. In high-payout advertising markets such as the US and UK, higher costs per click and per acquisition can justify heavier investment in evasion infrastructure — longer redirect chains, more domains, and deeper cloaking designed to survive scrutiny long enough to extract maximum value from each successful conversion. In lower-cost, higher-volume markets, a different model dominates: cheap, easily replicated, and easily discarded infrastructure that relies on sheer volume rather than sophistication, since profitability comes from a large number of attempts rather than a smaller number of highly engineered ones.

Both approaches share a common thread — they lean on distributed infrastructure rather than a single deceptive asset, just optimized differently for persistence versus scale.

What Defenders Should Watch For

Given this shift, security teams and ad-network reviewers should treat static, point-in-time inspection as necessary but no longer sufficient. Useful signals include:

  • Destination switching — a campaign’s final landing page changing after initial approval.
  • Repeated use of cloaking or fingerprinting logic that serves different content based on visitor characteristics.
  • Rapid domain churn or reuse of infrastructure across seemingly unrelated campaigns.
  • Multi-hop redirect chains where the true destination isn’t visible during initial review.

As one analysis put it, the central question has shifted from “what does this page contain right now?” to “where does the user actually end up, and does that change over time?” Until moderation and detection systems fully catch up to that reality, malvertising is likely to keep finding room to operate in the gap between a campaign’s approved appearance and its eventual behavior.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain, use the discussion on Forum.

>> forum community

Comments

Leave a Reply