Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure
Brief
Malvertising is becoming harder to identify by looking at the ad itself.
A growing share of malicious advertising activity now depends on what happens after the click: redirect chains, disposable domains, cloaking systems, conditional delivery, and campaign behavior that can change after initial approval. The creative or landing page may appear innocent, while the malicious component sits several steps deeper in the delivery chain.
The following analysis is based on campaign moderation data from PropellerAds, covering campaigns reviewed during the first half of 2026. At this scale, shifts in fraud infrastructure tend to become visible in the data before they’re widely recognized as a trend — this dataset is one example of that.
