Home Research Click Forensics CEO Pellman On The Malware And Malvertising Fronts

Click Forensics CEO Pellman On The Malware And Malvertising Fronts

SHARE:

Click ForensicsThe online advertising world continues to be challenged by ne’er-do-wells as Click Forensics released results from its latest quarterly, deep-dive into the company’s fraud detection data. The Company identified challenges with display advertising where “a pop-up or pop-under (…) rotates brand advertisers’ banner ads every 10-15 min in an effort to seemingly boost impression figures.” Read the release.

CEO Paul Pellman discussed the latest on malware and malvertising.

AdExchanger.com: How is the malware scheme you describe reaching websites – through display ads from exchanges, specific ad networks? Any ideas on how it can be prevented?

PP: The Click Forensics Malware Lab has been finding two generic types of malware.  The first, more common version, is actually installed on the visitor’s machine as a result of some other seemingly innocent download.  It can be spread via e-mail attachments or through lots of “freeware” that people install on their machines.  Once installed, these Botnets can take control of browser functions or simply open pop-unders to display ads for nefarious ad networks.  The best way to prevent these is for visitors to be diligent and use updated antivirus software from Symantec, McAfee, and others.

The second type is not really malware at all, but is the one more commonly talked about in AdExchanger circles.  Namely, visitors to ad supported sites get served all sorts of ads that they never see, whether in pop-unders, zero-by-zero iFrames, or invisible pages.  The generic term for these schemes is “ad stuffing.”  Advertisers can protect themselves from both types of fraud by employing ad verification and/or audience verification platforms.

What IS the malware? Any trends there?

Much of the malware we found recently came from different types of toolbars.  These are browser plug-ins that purport to assist with search or provide some other value for the visitor (weather, sports scores, etc.), but in reality are also hijacking browser activity for the benefit of the author.  One toolbar we found turned organic search results into paid clicks by routing searches to a parked domain site and channelling clicks through several ad networks.  It’s very difficult to trace which are complicit in the fraud and which are innocent participants.

From a marketer’s perspective, would using frequency caps or buying on a CPC basis might lessen the impact of inflation impression?

Frequency caps might help a display advertiser minimize the impact of these schemes, but it can’t defeat them completely.  As far as converting everything to CPC, it might work in the very short term but, as we well know, click fraud becomes an issue.  The best protection is the diligent monitoring of campaigns and the use of an audience/ad verification platform.

I didn’t see you mention malvertising versus malware in your release. Do you distinguish between the two?

We use “malvertising” to refer to ads that send visitors to a place that is bad for them.  The ad itself may not be infected, but its intention is to trick the visitor into doing something damaging.  For example, the ad on NewYorkTimes.com a little over a year ago warned visitors to click through to a site where they could “update their virus protection.”  Of course the download included all sorts of malware, but the ad itself was more accurately described as malvertising.

By John Ebbert

Tagged in:

Must Read

Amazon Crushes Earnings And Reaches Almost $20 Billion In Q2 Ad Revenue

Amazon’s advertising businesses earned a total $19.8 billion in Q2, the company reported in its quarterly earnings on Thursday. That’s up from $15.7 billion in Q2 2025, and good for a 26% year over year growth rate.

Los Angeles, California - 26 February 2023: Reddit social media platform displayed on smart device

Reddit Had A Great Q2, But Investors Have AI Search Jitters

Guess there’s no pleasing investors. Despite Reddit delivering an objectively solid Q2, its stock cratered, in part because of search-related headwinds and low referral traffic.

Meta’s Expenses Are Growing Faster Than Its Revenue, Thanks To Lawsuits And AI

A combination of layoffs, lawsuits and AI operating costs set back Meta’s Q2 earnings, despite increased revenue.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

Omnicom Investors Cheer IPG Sell-Off, Despite Weak Ad Spend In Q2

Omnicom is halfway through a major sell-off of IPG agencies. Its future looks healthier as it prunes lower-growth firms, including eliminating certain specialist firms and overlapping agencies in certain countries.

Hundreds of emails, depositions and other documents have been unsealed in the lead-up to the Google antitrust trial, providing a fascinating look at how Google talked about its own products when no one else was watching – especially tools to counteract the rise of header bidding.

Why PubMatic Ditched Its Prebid Web Wrapper, But Never Its SDK

Earlier this month, PubMatic shelved its Prebid integration wrapper, known as OpenWrap Web, and announced it would begin recommending Playwire as an offloading-onboarding partner for the 250-odd publishers that use its wrapper.

Gareth Glaser, Co-Founder & CEO, Gamera

Google’s Buyer Direct Could Beat Agentic Ad Tech At Its Own Game

Agentic AI shows promise for direct deals. But if Google has its way, Buyer Direct could put an end to all sorts of agentic direct sales opportunities while they’re still in the cradle.