Home Content Studio Malvertising Is Maturing, And So Must Our Industry

Malvertising Is Maturing, And So Must Our Industry

SHARE:

Only the strong survive: This has long been an inspirational tenet for ad tech, but it also describes the industry’s insidious malvertising problem.

Better technology and broader awareness have mostly constrained the most conspicuous breed of malvertising – forced redirects – that plagued us five years ago. What’s left now is a new strain of attacks that are more diverse, more profitable and harder to detect: malicious clickbait, tech-support scams and malware-infected software downloads.

The solution lies in another cliché: strength in numbers. Actions by individual publishers and platforms simply cannot keep pace with the agility of bad actors. Collectively, however, the industry has the force of its technical prowess to maximize its protection.

From bad to worse

In the good old days, the ubiquitous malvertising was driven by the easy-to-exploit Flash and drive-by downloads. Now Flash has been deprecated, the ad industry is investing in security vendors and browser security is maturing to better contain redirecting ad scripts. But the bad guys didn’t give up and switch to more honest pursuits just because drive-by downloads and forced redirects became less feasible. The smart ones found better, less conspicuous ways to compromise the ad tech infrastructure.

Today’s scammers use sophisticated cloaking techniques, disguising the real URL deep within the code of ad tags to sneak past automated ad scanning tech and manual QA. This cloaking also allows them to operate much more like legitimate advertisers and buy ad inventory on publisher sites, social media and in-app ad platforms.

These malvertisers then use speed and agility to their advantage, delivering malicious clickbait, tech support scams and malicious software downloads. The game has turned from Whac-A-Mole to cat and mouse.

Malicious clickbait is the most insidious of these new types of malvertising. A form of financial fraud, these cloaked investment scams have surged since 2019, when first reported by Confiant as FizzCore attacks. At one point, in 2021, they represented 90% of the attacks we detected.

Even recently, display ads were the primary vector for malvertising. Today, investment scams permeate every form of digital advertising – inside walled gardens; through in-app, native and video ads; and, of course, within display ads. And because users are often embarrassed to have fallen for these scams, much of the problem goes unreported.

A revenue-raiding scourge for ad tech

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

The result is a problem that appears quieter on the surface but is even more prolific – and much more damaging to users – than before. One in every 400 programmatic ads is malicious. And unlike tech-support scams and malicious software downloads, the impact of malicious clickbait is directly financial: The bad actors aren’t trying to infect a device or steal credentials. They are going straight for the user’s wallet.

The FTC estimates Americans lost over $1.7 Billion to investment scams in 2021, and 2022 was expected to well outpace that loss. That money isn’t just being stolen from unwitting users; it is money that won’t get properly invested into legitimate financial vehicles. Financial damage at that scale not only hurts the reputation of the publisher seen serving those ads but destroys the trust between users and the financial industry. The FTC also reported the damage is severe enough that it’s attracting government attention. The UK, with their Online Safety Programme, is actively reviewing their regulatory framework of paid-for online ads to tackle “the evident lack of transparency and accountability across the whole supply chain.”

Unsurprisingly, cautious users are installing ad-blocking software, threatening the ad revenue stream of all ad tech by decreasing the number of ad impressions served. Between 2014 and 2019, ad blocker penetration rates in the US increased from 15.7% to 25.8%. That number includes 100% of the US Intelligence Community.

A collaborative solution

The seemingly obvious answer here is for there to be supply-chain transparency so platforms and publishers can nip malvertising campaigns in the bud. But the problem is that enough entities have decided transparency is a threat to their business model and ad tech implements all of its transparency initiatives as one-way mirrors.

Modern malvertising preys on this lack of transparency. To overcome it, both sides of the industry must learn to act as partners. Initiatives like DemandChain Object, Buyers.json and client-side disclosures of Creative IDs (CRIDs), slow moving as they are, represent our best hope of concretizing the gains of the past five years before the malvertising game evolves again into something even worse.

Must Read

Intent IQ Has Patents For Ad Tech’s Most Basic Functions – And It’s Not Afraid To Use Them

An unusual dilemma has programmatic vendors and ad tech platforms worried about a flurry of potential patent infringement suits.

TikTok Video For Open Web Publishers? Outbrain Built It.

Outbrain is trying to shed its chumbox rep by bringing social media-style vertical video to mobile publishers on the open web.

Billups Launches Attention Measurement For Out-Of-Home

Billups, a managed services agency that specializes in OOH, is making its attention measurement solution and a related analytics dashboard available for general use.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
US District Court for the Eastern District of Virginia, Alexandria

The Google Ad Tech Antitrust Case Is Over – And Here’s What’s Happening Next

Just three weeks after it began, the Google ad tech antitrust trial in Virginia is over. The court will now take a nearly two-month break before reconvening for closing arguments right before Thanksgiving.

Jounce Media's Chris Kane at Programmatic IO NY on Sept. 25, 2024.

The Bidstream Is A Duplicative, Chaotic Mess – But It Doesn’t Have To Be That Way

Publishers are initiating more and more auctions – but doesn’t mean DSPs are listening to more bids, according to Chris Kane.

Readers Are Flocking To Political News, Says WaPo – And Advertisers Are Missing Out

During certain periods this year, advertisers blocked more than 40% of The Washington Post’s inventory over brand safety concerns.