Posted in

5 Ways to Protect Your Enterprise from Malvertising

A desktop monitor displaying an Aegis Cyber-Intelligence security dashboard highlighting an evaluation agent lateral movement breach from an internal system to Hugging Face production servers.
Security monitoring interface demonstrating lateral movement pathways and cross-environment data leaks during autonomous AI evaluation agent testing.

Cybercriminals are a constant thorn in the side of every IT professional. That said, it’s hard not to admire the inventiveness and determination that goes into many hacking campaigns.

The emergence of malvertising as a mainstream industry is a prime example. In 2017, a single group of hackers managed to spread malware-infected adverts to 62% of the web‘s ad-monetised websites on a weekly basis. They did so using a network of fake advertising agencies, complete with bogus executive LinkedIn profiles and phoney social media presences. What’s more, they did it all without really having to get their hands dirty.

The eventual payload of a malvertising campaign isn’t particularly new or sophisticated; It’s generally all about infecting computers with malware using things like fake Adobe Flash updates and dishonest scareware internet security programs. The clever part is how the hackers now spread the malware via legitimate advertising networks, giving themselves a reach across millions of websites. And by no means are most of these sites dodgy .

Instead, the criminals work out ways to place their infected ads on sites people generally regard as safe places.

How Does Malvertising Work?    

On a simple level, a hacker could launch a small malvertising attack simply by purchasing an advert on a popular website. By including malicious code within the advert (and successfully getting it past the webmaster and published), the hacker could redirect ad clicks to malware-infected sites or even include code that could infect the device of anyone viewing the ad.

However, like the entrepreneurs they resemble, cybercriminals think big. In this case, they found a way to scale their approach. To understand how it works, let’s step back and consider how online advertising works today.  

Companies spend over $220 billion per year on online advertising, and the figure increases every year. Many websites, from the smallest of blogs to the largest of news outlets, display adverts to earn revenue and make running the sites worthwhile.

Although some advertising deals are negotiated individually between websites and advertisers, the industry is so enormous that most web publishers instead sign up with one or more advertising networks. Publishers allocate spaces on their sites where the networks can place ads, effectively relinquishing control of these areas to the networks which, in return, source advertisers and secure revenue for the sites. These networks, in turn, work with advertisers and advertising agencies to find the adverts that they place on participating sites.

This is where cybercriminals stepped in, with their fake ad agencies. Over time, they gained the trust of ad networks, which gave them the freedom to spread their malicious ads on an enormous scale, and onto the websites of customers of the legitimate ad networks. It’s worth noting that this is a hugely simplified explanation; hackers also employ techniques that enable their malware ads to evade electronic detection, and even build in the ability to sell hijacked traffic on to other criminals.

How to Protect Against Malvertising

The thing that makes malvertising so effective is that internet users are accustomed to seeing ads and do often click on them. Thanks to techniques such as pop-ups and pop-unders, people also often end up clicking on them unintentionally.

Add to this the fact that hackers have now found a way to widely insert their malicious ads in sites that the average user wouldn’t expect to be compromised, and you have a dangerous situation.

Here are some steps IT departments can take to address this threat:

1. Consider disabling Java and Flash

Java and Flash were once integral parts of the online world, but today they’re both primarily infamous for security vulnerabilities. HTML5 has also rendered them increasingly outmoded.

As such, the time has come to seriously weigh whether to disable both Java and Flash company-wide. For many firms, these platforms are not in regular use any more and are no longer necessary. Allowing use for specific purposes on a case-by-case basis is always an option here, but the more use of Flash and Java is minimised, the fewer opportunities hackers have to exploit these systems as part of their malware payloads.

2. Ensure Antivirus is Installed and Updated

While it’s fair to say that the kind of malware deployed by malvertising aims to evade traditional antivirus products, their use remains essential. Even if a malicious advert is clicked, an antivirus product may successfully step in and stop the related malware from doing further damage.

Running an up-to-date and reliable antivirus should always be mandatory on any company network. It may not prevent malvertising, but in many cases, it remains a valuable form of defence.

3. Keep Browsers Updated

Keeping web browsers up to date is an essential step to protect against malvertising. With new vulnerabilities being discovered in browsers all the time, keeping them patched should be a given in any case. IT teams should ensure these updates are deployed centrally and not left to users.

As a specific example of the importance of this, Google blocked forced redirects in Chrome in early 2017, as a direct move to combat one of the tactics employed in malvertising.   

4. Use a Remote Browser Isolation (RBI) Solution

RBI is a great way to provide a true level of protection from malvertising and other browser-based threats.

Remote Browser Isolation (RBI) keeps online content safely segregated from the live enterprise network. RBI works invisibly for users, who browse normally, but if any malware is unleashed, it’s isolated in a remote location and is thus unable to infect the user’s computer. With browsing activity safely contained, the network stays safe.

5. Educate Staff

Staff education is a crucial part of IT security, and all system users must understand the part they play in keeping networks safe. Informing staff of new threats and system changes should happen regularly and routinely.

As an example, companies deciding to disable Flash and Java, as suggested above, should inform staff of the change, so that they are aware that any pop-up asking to update these plugins cannot be genuine, but is most likely malicious.

Malvertising, on the scale described above, demonstrates how resourceful and cunning modern hackers can be. Thankfully, IT departments can be resourceful too – something proven by the emergence of solutions like Remote Browser Isolation, which directly respond to the ongoing, dangerous evolution of malware threats.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.