You can be on the right website and still be looking at the wrong advertisement.
That is the uncomfortable part of malvertising.
Microsoft defines malicious advertising as a situation in which an attacker submits malicious content to an advertising network and that content is then hosted by a benign website. Its SmartScreen documentation even includes a demonstration scenario described as a benign page hosting a malicious advertisement.
See Microsoft’s SmartScreen explanation of malvertising.
The publisher does not have to be the attacker.
The ad can come from somewhere else
Modern websites often sell advertising space through networks and exchanges rather than selecting every advertisement manually.
The page belongs to the publisher. The ad may be supplied through an external advertising chain.
That separation is useful for legitimate advertising because it lets publishers fill inventory automatically. It also creates a place where malicious creatives, redirects, fake warnings, or dangerous destinations can enter the page without the site’s ordinary editorial content being compromised.
Google’s own Ad Manager documentation warns publishers about ads that trigger automatic redirects or pop-ups and classifies them as malvertising. Google says it scans creatives and blocks malicious content, while also noting that third-party exchanges and other demand sources may have different protections.
See Google’s Ad Manager guidance on malware in ad content.
Trust in the host leaks into the advertisement
Users rarely think about the supply chain behind a rectangle on a webpage.
If the surrounding site is familiar, the advertisement benefits from the site’s reputation. A fake update, fake security warning, investment offer, or download button can feel less suspicious because it appeared inside a place the user already trusts.
But ad placement is not an endorsement of the destination.
Microsoft notes that malicious ads can redirect users to phishing sites, initiate unwanted downloads, or push people toward further social-engineering steps.
Treat the click as a new destination
A reputable publisher is evidence about the publisher.
It is not proof about every advertiser delivered through that page.
Before entering credentials, downloading software, or paying for something reached through an ad, inspect the destination as a separate site. Check the domain. Reach the company independently if the offer involves an account or service you already use. Prefer the vendor’s known website for downloads and sensitive transactions.
Malvertising exploits a mental shortcut that normally works well: I trust this place, therefore the things inside this place are probably safe.
Advertising networks make that conclusion less reliable.
The webpage can be legitimate while one rectangle inside it is somebody else’s trap.
