CyberSecurityNews

Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure


Malvertising is becoming harder to identify by looking at the ad itself.

A growing share of malicious advertising activity now depends on what happens after the click: redirect chains, disposable domains, cloaking systems, conditional delivery, and campaign behavior that can change after initial approval. The creative or landing page may appear innocent, while the malicious component sits several steps deeper in the delivery chain.

The following analysis is based on campaign moderation data from PropellerAds, covering campaigns reviewed during the first half of 2026. At this scale, shifts in fraud infrastructure tend to become visible in the data before they’re widely recognized as a trend — this dataset is one example of that.

Malware and antivirus-flagged threats rose from 8,408 rejected campaigns in Q1 to 9,543 in Q2 — a 13% increase in absolute terms, at a time when total rejections fell 42% (36,085 to 20,790). As a share of all rejections they went from 23.3% to 45.9%, becoming the largest category. Much of that shift in share reflects adult-content violations being filtered out earlier in moderation (47.8% to 5.3%). The substantive point is that technical threats kept growing while straightforward content violations collapsed. Overall campaign rejections dropped by 42%, from 36,085 to 20,790.

Taken together, the numbers point to a marked change in the composition of rejected campaigns. Straightforward content violations are becoming easier to stop earlier in moderation, while a greater share of rejections now involves technical threats that are harder to evaluate through a single static check.

Independent industry data showed the same shift a year earlier. GeoEdge found redirect-based attacks rising from 48% of malicious activity in Q1 2025 to 66% in Q2 2025, while malicious ad activity doubled across the five largest markets it monitored. Overall malicious ad activity doubled across the five largest markets it monitored. Google’s H1 2026 threat telemetry, meanwhile, found malvertising accounted for almost 30% of its threat detections, underlining how closely malicious advertising now overlaps with the broader consumer cybersecurity landscape.

Cloaking reinforces the same pattern in the PropellerAds dataset. It accounted for 67.3% of advertiser suspensions in Q2, almost unchanged from 68.1% in Q1 — evidence that hiding a campaign’s real destination or behavior is a persistent operating tactic, not an occasional evasion technique.

The malicious asset is increasingly the chain, not the page

Traditional ad review begins with visible elements: the creative, landing page, offer, and directly associated domains. That approach becomes less effective when malicious behavior is distributed across several technical components.

A campaign may begin with an apparently compliant ad and a clean landing page, then route the user through tracking services, intermediate domains, conditional redirects, or additional pages before reaching the final destination. Each stage may look harmless in isolation; the risk only becomes visible when the full path is reconstructed.

The Media Trust’s 2026 Digital Advertising Intelligence Report describes a similar problem: malicious creatives are increasingly designed to, as the report puts it, “activate only under particular geographic, device, or behavioral conditions”, making one-time detection less reliable.

This architecture gives malicious operators several advantages. It separates the original ad from the eventual payload. Individual domains can be replaced without rebuilding the whole operation. Traffic can be segmented by geography, device, or other signals so different visitors see different outcomes.

A recent malvertising campaign investigated by Confiant illustrates the model. Active since late 2024, it impersonated brands including TradingView, Solana, and Luno across 12 countries and 25 languages. Its landing pages fingerprinted visitors: suspected researchers and bots received an empty page, while selected targets saw convincing copies of the impersonated services.

The campaign is therefore no longer a single malicious object. It is a delivery system.

A static inspection asks: what does this page contain right now? Infrastructure-aware analysis has to ask where the user goes next, whether that destination changes, and whether the same campaign behaves differently hours after approval. The deeper malicious behavior moves into the delivery chain, the less useful a one-time assessment becomes.

Fraud infrastructure follows market economics

The Q2 observations also suggest that traffic economics can influence the form malicious advertising takes — and that the distinction is economic as much as geographic.

In high-payout markets, including Tier-1 geographies such as the US and UK, higher CPC and CPA values can support greater investment in evasion infrastructure: longer redirect chains, multiple domains, and deeper-funnel cloaking. The economic logic favors persistence—surviving scrutiny long enough to extract greater value from each successful conversion.

For defenders, that makes signals such as destination switching, cloaking, and infrastructure reuse especially relevant.

In lower-cost, high-volume markets, a different model becomes viable. Infrastructure can be cheaper, easier to replicate, and easier to discard, with profitability depending on distributing many attempts rather than heavily engineering a smaller number of campaigns.

In high-volume environments, replication signals — rapidly changing domains, reusable templates, and large clusters of similar campaigns — may therefore matter more.

Both models rely increasingly on infrastructure rather than a single deceptive page. They simply optimize that infrastructure for different conditions: persistence in one case, scale and replaceability in the other.

Multi-hop redirects create a visibility problem.

Redirect chains separate the point where a user enters a campaign from the point where malicious behavior occurs. The path may include several intermediate domains, tracking services, conditional redirects, or other routing layers before the user reaches the final destination. 

Each additional hop creates another opportunity to change behavior. One domain may exist for tracking, another for a device or location check, another to decide the final destination. Some users may see a benign page while others are sent to a malicious endpoint.

This complicates moderation in several ways. The final destination may not be visible during the initial review. Malicious domains can be short-lived and replaced once blocked. Infrastructure can behave selectively according to location, device, or other visitor characteristics. The chain itself can also change over time.

GeoEdge’s data again shows how prominent this technique has become: auto-redirects accounted for 66% of malicious advertising activity in its Q2 2025 dataset, while 21% of malicious ads used cloaking to conceal their true content.

The gap between what is checked and what a targeted user ultimately receives is precisely what makes cloaking and multi-stage delivery effective.

Moderation has to become behavioral

When malicious advertising depends on behavior rather than static content, moderation has to follow the same logic. Initial checks remain necessary, but they are only one part of the process.

More effective controls increasingly rely on repeated observation: following redirect chains, comparing campaign behavior under different conditions, and revisiting previously approved campaigns for changes after launch.

Automated systems matter because the number of possible campaign paths quickly exceeds what manual review can examine consistently. Human investigation remains necessary for ambiguous cases and new techniques, but automation makes repeated revisiting feasible at scale.

The Q2 data also suggests how quickly abusive campaigns can adapt to new moderation controls. Adult content fell from 47.8% to 5.3% of campaign rejections reasons after preventive filters were strengthened, yet appeared as the second-largest reason for advertiser suspensions, at 15.9%, in the same quarter.

One interpretation is that some operators adjusted their methods to pass initial review and exposed prohibited content only after campaigns went live. Successful filtering may therefore change where a violation surfaces rather than remove the underlying incentive.

What the advertising ecosystem should monitor

For advertising platforms, infrastructure-based threats mean looking beyond submitted creatives and landing pages. Redirect depth, destination changes, infrastructure reuse, conditional behavior, and post-launch changes can all reveal risks that a static check may miss.

Publishers should watch for unexpected redirect behavior and changes in advertiser destinations. Brands and security teams should monitor lookalike domains, impersonation, and paid-traffic paths leading users toward fraudulent assets.

Regional context matters too. A pattern associated with persistence and complex evasion in a high-payout market may require different controls from large clusters of short-lived, highly replicable campaigns in a high-volume market.

Ad moderation can also act as an early threat signal

Advertising moderation can provide an early view of emerging abuse because new phishing techniques may already be circulating through ad channels before they are widely documented.

PropellerAds analysts saw this pattern in WhatsApp phishing flows, where attackers used familiar messaging platforms and device-linking or authorization mechanics as part of account-takeover schemes. Similar techniques later appeared in broader public threat reporting, including WhatsApp GhostPairing and Telegram phishing campaigns using cloaking and selective delivery.

This does not make moderation data a predictive system for cybercrime. But repeated appearance of the same unusual delivery mechanism or infrastructure pattern across rejected campaigns can be a useful threat-intelligence signal, not just a moderation statistic.

The takeaway

A global advertising platform cannot assume one fraud profile applies equally everywhere. Differences in traffic price, payout structure, and scale change what attackers optimize for — and what defenders need to watch.

As detection improves at the content layer, the incentive shifts deeper into redirects, domains, conditional delivery, and post-launch behavior. Evaluating a campaign increasingly means asking not just what an ad says, but what it does — over its full lifetime, not only at the moment of approval.

Methodology: The analysis is based on advertising campaigns submitted to the PropellerAds network during Q1 and Q2 2026, reviewed and classified by PropellerAds’ internal moderation and security team. The dataset includes campaign rejection and advertiser suspension reasons recorded during the moderation process. Percentages describe the composition of rejected or suspended campaigns within this dataset and should not be interpreted as estimates of prevalence across the wider advertising industry.

Author: Farukh Rakhimov, Head of Compliance, Data Protection and Information Security at AdTech Holding



Source link