Growing Complexity in Malvertising Threats
Malicious advertising, or malvertising, is increasingly difficult to detect through superficial examination of the ad alone. The real threat often lies in what happens after the ad is clicked. This includes redirect chains, use of disposable domains, cloaking systems, and dynamic campaign behaviors that can change post-approval. While the ad creative or landing page may seem harmless, the malicious elements are embedded deeper within the delivery chain.
Shifts in Ad Fraud Infrastructure
Data from PropellerAds, analyzing campaigns from the first half of 2026, reveals noticeable shifts in fraudulent infrastructure. Malware and antivirus-flagged threats increased by 13% from Q1 to Q2, despite a 42% overall drop in campaign rejections. Notably, technical threats have grown while straightforward content violations have declined due to earlier detection. This trend mirrors independent industry findings, such as GeoEdge’s report on increasing redirect-based attacks and Google’s telemetry data highlighting malvertising’s significant role in cybersecurity threats.
The Role of Cloaking and Redirection
Cloaking remains a persistent tactic in malvertising. In Q2, cloaking accounted for 67.3% of advertiser suspensions, indicating a consistent strategy to hide true campaign destinations or behaviors. Traditional ad review processes, focusing on visible elements like the ad creative or landing page, are less effective against such distributed malicious behaviors. Campaigns may initially appear compliant but redirect users through complex paths involving tracking services and intermediate domains before reaching the final, often malicious, destination.
Reports, including The Media Trust’s Digital Advertising Intelligence Report, highlight how malicious creatives are designed to activate under specific conditions, such as geographic or device-based triggers, making them difficult to detect in single checks. This architecture allows malicious operators to separate the original ad from its ultimate payload, adapting to evasion tactics and optimizing for persistence or scalability based on market economics.
Economic Influences on Malvertising Strategies
The form that malvertising takes can be influenced by economic factors, especially in high-payout markets like the US and UK. Here, higher CPC and CPA values justify investment in sophisticated evasion infrastructures, such as longer redirect chains and multiple domains. Conversely, in lower-cost markets, the focus shifts to high-volume distribution with easily replicable infrastructure.
These economic drivers necessitate different defensive strategies. In high-payout markets, defenders must focus on signals like destination switching and infrastructure reuse. In contrast, high-volume markets require attention to rapid domain changes and campaign replication signals.
Adapting to Infrastructure-Based Threats
As malvertising increasingly relies on infrastructure rather than a single deceptive page, moderation strategies must evolve. Initial static checks are insufficient; ongoing behavioral analysis is crucial. Automated systems are essential for tracking redirect chains, comparing campaign behaviors under various conditions, and revisiting previously approved campaigns to detect post-launch changes.
PropellerAds’ Q2 data indicates how quickly abusive campaigns can adapt to new moderation controls. While adult content violations decreased significantly due to strengthened filters, they remained a prominent reason for advertiser suspensions. This suggests operators are adapting their methods to initially bypass reviews, exposing prohibited content only after launch.
For advertising platforms, identifying threats involves looking beyond submitted creatives and landing pages. Observing redirect depth, destination changes, and post-launch behavior can reveal risks missed by static checks. Brands and security teams need to monitor for impersonation and fraudulent traffic paths, especially in regional contexts where threat patterns may vary.
Overall, as detection improves at the content layer, malvertising tactics will continue to move deeper into the infrastructure, demanding more sophisticated monitoring and analysis to protect users and platforms alike.
