Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Targeted advertising uses data to help businesses show ads to selected audiences. Malvertising is different: it uses malicious or hijacked online ads to spread malware. The two can overlap when attackers tailor a malicious ad campaign to particular victims, but ordinary personalized ads are not themselves malware.

What targeted advertising and malvertising mean

The Federal Trade Commission’s 2020 primer describes targeted online advertising as the collection and use of personal data to help firms reach potential customers. The term describes how an audience is selected; it does not mean an ad is malicious.

The Cybersecurity and Infrastructure Security Agency (CISA) defines malvertising as “the use of malicious or hijacked website advertisements to spread malware.” Its guide for federal agencies says attackers can place malicious ads in legitimate ad networks, make them redirect visitors, or use them to load a malicious payload. An attacker may also tailor an ad campaign to a specific victim.

How a malicious ad can lead to malware

An ad does not have to look suspicious, and a legitimate website can display an ad that was supplied through an ad network. A familiar site’s reputation therefore does not prove every ad on it is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Redirect: An ad can send a visitor to an unexpected website or open a pop-up. Google Ad Manager identifies automatic redirects and pop-ups as forms of malvertising. Google scans ad creatives and prohibits certain behaviors, but warns that third-party exchanges, networks, and integrations may not provide the same protections. Those controls apply to Google’s platform, not the entire advertising ecosystem. See Google Ad Manager’s guidance on preventing malware in ad content.
  • Cloned download site: A malicious ad can lead to a site that imitates a software vendor and offers a download containing malware. The FTC describes this route in its consumer alert about ads for fake AI and other software.
  • Compromised software download: An ad may promote software that appears genuine, while the delivered download contains a malicious backdoor. Google’s May 2025 company advisory describes malvertising as a tool used by bad actors and notes that it can be an early step in a larger abuse chain. Potential consequences include stolen information or compromised accounts.

Google’s advisory also discusses campaigns aimed at people with valuable online assets or other selected groups. Such targeting describes the attacker’s choice of victims; it does not turn legitimate audience-targeted advertising into malware.

What the available figures do—and do not—show

The published figures below measure different things and should not be read as a current estimate of how common malvertising is across the internet.

Figure What it measures What it does not establish
More than 5% of unique daily IP addresses accessing Google Google Research authors’ 2015 study of ad injection; the figure describes the study’s measured ad injection. It is not a current estimate of all malvertising. Source: Thomas et al., “Ad Injection at Scale”.
50,870 Chrome extensions and 34,407 Windows binaries; 38% and 17%, respectively, classified as explicitly malicious Client-side vectors identified and classified in the same 2015 ad-injection study. These counts and classifications describe that study, not today’s extension or malware totals. Source: Thomas et al., “Ad Injection at Scale”.
Over 1 billion advertisements blocked or removed during 2023 Google’s 2024 report of ads blocked or removed for violating its policy against abuse of Google’s ad network, which includes promotion of malware. It is not a count of malware infections or a measure of the whole advertising industry. Source: Google’s 2023 Ads Safety Report.

The sources cited here do not establish a current overall prevalence estimate for malvertising. The historical research measurement and Google’s platform-specific enforcement count are not directly comparable.

How to reduce the risk as an individual

  1. Do not use an ad as the route to a software download. The FTC advises users who see an ad for software they want to try to type the vendor’s known address instead of clicking the ad. If you do not know the address, find it through a trusted source rather than following a download ad. See the FTC consumer alert.
  2. Keep devices and software updated. Install updates for your operating system, browser, phone, and security software; enable automatic updates where available.
  3. Treat unexpected redirects and download prompts as warning signs. Close a page that redirects unexpectedly, and do not install software simply because an ad or pop-up says it is required.

Controls for organizations and agencies

CISA’s recommendations are federal-agency security guidance, not a requirement that every household buy equipment. Organizations can select layered controls based on their environment, users, and risk:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Standardize and secure web browsers.
  • Deploy advertisement-blocking software where appropriate.
  • Isolate browsers from operating systems to limit the consequences of a compromised browsing session.
  • Implement protective DNS technologies.
  • Consider network controls such as web proxies, DNS sink-holing, web filtering, and firewalls.

CISA describes these measures in its browser security and malvertising guide. No single measure guarantees that every malicious ad or download will be blocked.

If you operate a website or investigate a suspicious ad

For a publisher or ad operator, investigation depends in part on which demand source served the creative. Google Ad Manager recommends collecting context that can help troubleshoot an unwanted ad, including a full-screen screenshot, browser and operating-system details, system time, and click information. Its troubleshooting guidance explains the information to gather and notes that investigation and blocking options vary by demand source.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Related malware-delivery tactics are not all targeted advertising

The FBI’s Internet Crime Complaint Center has described malicious traffic distribution systems that route visitors differently based on location or other characteristics, and that can be used to distribute malware. Its June 2026 advisory also tells users to avoid plugins and themes from unverified developers. This is related evidence about traffic routing and malware delivery; it does not show that every such scheme uses targeted advertising.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.