#malvertising
Malicious advertising used to redirect victims to phishing pages or trigger drive-by malware downloads
IOCs by window
6
IOCs tagged #malvertising
24
IOCs tagged #malvertising
32
IOCs tagged #malvertising
32
IOCs tagged #malvertising
Counts as of 2026-08-22. Regenerated daily.
About #malvertising
- Definition: the abuse of online advertising platforms to distribute malicious content. An adversary buys or injects an ad that looks legitimate; clicking it - or, in some drive-by variants, just loading the page - redirects the victim to attacker infrastructure. MITRE ATT&CK T1583.008.
- Where it shows up: search-engine ad slots for popular software (browsers, PDF readers, remote-access tools), display ads on legitimate high-traffic sites, and ad networks with weak vetting. Clicking the ad leads to a cloned download page or an exploit landing page instead of the real vendor.
- Evasion: operators commonly cloak the ad: the ad network's own review crawler sees a benign page, while real visitors matched by IP range, user agent or referrer get redirected to the malicious destination. This keeps the payload hidden from the platform doing the vetting.
- References: MITRE ATT&CK T1583.008.
Recent IOCs tagged #malvertising
Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/malvertising.
| Date | Type | Value | Source |
|---|---|---|---|
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url |
Related tags
Frequently asked questions
What is malvertising?
Malvertising is the abuse of online advertising to distribute malicious content. An adversary buys ad space or compromises an ad network, then serves an ad that looks legitimate - often impersonating a well-known brand or piece of software. Clicking the ad, or in some cases just loading the page it appears on, redirects the victim to a phishing page, a cloned download site or a drive-by exploit. MITRE ATT&CK tracks it as T1583.008.
How is malvertising different from a compromised website?
A compromised website is the attacker's own foothold: they altered a real site's code directly. Malvertising instead abuses a third-party advertising platform to plant malicious content on ad slots embedded across many unrelated, otherwise-legitimate sites, without touching those sites' own code. The two are often chained: a malvertising click can land on a compromised site that hosts the actual payload.
How is this list updated?
Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Malvertising-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.
What is the license? Can I use this commercially?
All TweetFeed IOC data, including this Malvertising subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.
License
Malvertising IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).