Malvertising: Ad-tech surveillance is a security problem now

Malicious ads running on legitimate platforms compromised nearly one million devices in a single campaign detected in December 2024.

Contributed Content

malvertising
Your office ad feed is also an attack surface. Malvertising beat phishing as the top malware vector every quarter of 2024. Image created with TechNation's TN:AI Workflow for illustration purposes.

Topics: 

Topics: 

Sharing is caring! 

Advertising technology has spent years building detailed profiles of every device that loads a webpage. Attackers figured out they could rent that same infrastructure to walk straight into your network. This is called malvertising.

Malvertising (embedding malware or redirect traps inside legitimate-looking online ads) is not a brand new phenomena. It ranked as the number one initial infection vector across all tracked malware for every quarter of 2024.[1]

It even beat email phishing.

Malvertising is a thing now….

The scale of what that exposure looks like in practice became clear in early December 2024, when Microsoft Threat Intelligence detected a campaign that went on to compromise nearly one million devices globally.[2]

The attackers embedded malicious redirectors inside ads running on illegal streaming sites.

Users were bounced through two or more intermediate sites before landing on GitHub repositories loaded with information-stealing malware. The campaign hit consumer and enterprise devices indiscriminately.

How malvertising works

The mechanics are straightforward.

Attackers purchase ad placements through real advertising platforms and route victims to convincing fake software sites. They do not need to hack the websites your staff visit. They only have to buy a slot in the ad auction and the ad network delivers the payload for them.

In 2025, The Media Trust how advertising infrastructure was increasingly recognised by regulators and media companies as part of the cyber risk landscape.[3]

Their data comes from analysis of more than 200 billion ads monthly across over 100,000 digital properties. One in five ad impressions worldwide is now classified as invalid or unsafe.

The threat in South Africa

For South African businesses, this is not an abstract global problem.

Check Point reported that local corporate organisations each face an average of 1,863 attacks per week. Cybercrime cost the country’s telecoms sector alone R5.3 billion in 2025, according to industry body Comric.[4]

The threat also comes through legitimate professional platforms. In May 2025, Mandiant tracked a campaign by a group designated UNC6032 that created counterfeit websites promoted through Facebook and LinkedIn ads, disguised as AI video tools. The downloads deployed Python-based infostealers and backdoors.[5]

Your staff clicking on what looked like a Canva feature is how that starts.

Sources:
[1] Center for Internet Security. Top 10 Malware Q4 2024.
[2] Microsoft Threat Intelligence. Malvertising campaign leads to info stealers hosted on GitHub.
[3] The Media Trust. 2026 Intelligence Report: When Advertising Entered the Cyber Conversation.
[4] Business Day. Cybercrime cost South Africa’s telcos R5.3bn in 2025.
[5] Mandiant & Google Cloud Security. Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites.

Before you @ us:

No, AI did not “write this article.” Calm down. This piece was produced using our TN:AI newsroom workflow. The opinions and typos belong to a human who has algorithmic side quests. (Hi!) We even wrote an AI policy so nobody panics.

🧠 AI-assisted research + summarisation 📝 Human edited + fact-checked

Sharing is caring! 

Featured reads: