Malvertising, a portmanteau of malicious software and advertising, is the use of online advertising to spread malware, typically by injecting malicious or malware-laden advertisements into legitimate online advertising networks and webpages. Because advertising content can be inserted into high-profile, reputable websites, the technique lets attackers reach users who might otherwise avoid or be protected from their attacks by firewalls or other safety precautions, and it can be spread across a large number of legitimate websites without directly compromising any of those websites themselves. Infections delivered through malvertising typically require no action from the user, such as clicking, and exploit no vulnerability in the website or server hosting the advertisement; the malicious code instead travels silently through the advertisement itself. The technique has grown rapidly and is difficult to combat: in 2012, an estimated nearly ten billion ad impressions were compromised by malvertising, and companies and websites have had difficulty reducing the number of malvertising attacks.
Facts
Elements of OffenseUse of online advertising to spread malware, typically by injecting malicious ads into legitimate ad networks and webpages 1 Notable ExampleLos Angeles Times malvertising attack, 2012 1 Classification
Offense GradeMinor or Summary Offense 1 Connections
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
Sources
1. Malvertising (Wikipedia)
Lead paragraph, first sentence
the use of online advertising to spread malware
History
In 2012, the Los Angeles Times was hit by a massive malvertising attack which used the Blackhole exploit kit to infect users.
View the SourceReader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.