All systems operational · Ormskirk, North West England

Beware These Common Malvertising Attacks

Malvertising uses online adverts to deliver malware, steal passwords, or defraud your staff. Here are the three most common techniques and how to protect your business against them.

What Is Malvertising?

Malvertising, short for malicious advertising, is the use of online adverts to deliver malware, steal credentials, or defraud users. The attacks range from fake technical support scams to drive-by downloads that install malicious software without a single click.

What makes malvertising particularly dangerous for businesses is that adverts can appear on entirely legitimate, well-known websites. You do not need to be on a suspicious site to encounter one. And with outdated browsers, simply loading a page containing a malicious advert can be enough to compromise a device.

Three Common Malvertising Techniques

1. Scam Malvertising

An advert appears claiming your computer is infected and instructing you to call a phone number for support. If a member of staff calls the number, they will be pressured into installing software that hands control of the device to the attacker. A fee is then charged to “fix” a problem that never existed. This technique targets anyone who panics at the sight of a security warning.

2. Fake Installer Malvertising

Adverts lead users to cloned websites that closely resemble trusted brands. The user downloads what appears to be legitimate software but instead installs malware. The domain name is usually slightly altered, for example a swapped letter or an added word, making it easy to miss on a quick glance. Always check the exact URL before downloading anything.

3. Drive-By Download Malvertising

This is the most insidious technique. It exploits vulnerabilities in outdated browsers to install malicious files or extensions automatically, without any interaction from the user. The device can be compromised just by loading a page that contains the advert. Keeping browsers updated is one of the most effective defences against this type of attack.

How to Protect Your Business

Train your team to question urgency

Malvertising relies on panic. Any advert or pop-up that demands immediate action, claims your device is infected, or urges you to call a number should be treated with scepticism. A real security alert from your IT systems does not come through an online advert.

Check links before clicking

Before clicking any link within an advert, check the destination URL carefully. If it does not match the genuine domain of the brand being advertised, do not proceed. Attackers often use domains that look plausible at first glance.

Keep browsers updated

Browser updates patch the vulnerabilities that drive-by download attacks exploit. Ensuring all staff are running the latest browser version is a straightforward step that removes a significant attack vector.

Build a culture of cyber awareness

Your staff are your first line of defence. Regular, practical awareness training, covering how to spot suspicious adverts and what to do if something looks wrong, reduces the risk across your whole business.

Support Across the North West

Blowfish Technology supports businesses across the North West, including IT Support Manchester, IT Support Chester, IT Support Warrington, IT Support Runcorn, IT Support St Helens, and IT Support Widnes.

If you want to prepare your team to recognise and avoid malvertising attacks, get in touch. We can help you build a practical cyber security awareness programme that fits your business.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.