Malvertising: How Fake Software Ads Are Infecting Small Businesses

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, an Active Top Secret Clearance, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

Every employee has, at some point, needed to download a piece of software right now: a terminal tool for a quick server fix, a PDF editor for a client file, a Zoom update before a call in five minutes. That moment of "I just need this to work" is exactly what malvertising is built to exploit. Instead of hacking a network directly, attackers buy a legitimate ad placement on a search engine, position it above the real vendor's own link, and let the employee do the rest by clicking the first result and running whatever it downloads. It's become one of the most efficient ways into a small business in 2026, because it doesn't need a phishing email, a vulnerable server, or a stolen password. It just needs someone to search for software the normal way.

How a malvertising attack actually works

Attackers register a domain that looks close enough to a real vendor's, build a landing page that's a pixel-perfect copy of the legitimate download site, and buy a sponsored ad slot for the software's name and common misspellings. Because ad platforms review submissions quickly and campaigns can be swapped after approval, the ad frequently starts clean and is switched to the malicious version, or rotated to a fresh malicious domain, after it's live. A search for "PuTTY download," "Notepad++," or "QuickBooks tool support" can put the fake result at the very top, ahead of the real vendor, with a URL that reads correctly at a glance. The file that downloads is often a legitimate installer wrapped around a malicious payload and signed with a stolen or cheaply purchased code-signing certificate, so it doesn't trip the "unknown publisher" warning most people have learned to watch for. Some campaigns install the real software so nothing looks wrong, while quietly dropping an info-stealer, remote access tool, or loader in the background.

Why this matters for a small business

  • It targets the moment people trust most. A sponsored result at the top of a search page reads as more official, not less, to most users, and ad blockers that strip banner ads and tracking scripts don't touch a search engine's own sponsored listings.
  • It outruns reputation-based defenses. Malicious landing pages and download domains often rotate every few hours, faster than many blocklists and antivirus signature updates can keep up, so a domain can be "unknown" or "clean" in a filter's eyes right up until the moment it's clicked.
  • It hides in tools IT can't just ban. PuTTY, WinSCP, PDF editors, and messaging apps are things employees legitimately need, so the fix can't be "never download software," it has to be "never let employees be the ones deciding where it comes from."
  • The payload is rarely limited to one machine. An info-stealer harvests saved passwords and session tokens that open the door to email, file storage, and line-of-business accounts well beyond the one laptop that got infected.

What actually stops it

  • DNS and web filtering that blocks known malvertising and newly registered domains at the network level, before the fake landing page or its payload can ever load.
  • Removing local admin rights from standard employee accounts, so a downloaded installer can't silently gain the permissions it needs to plant a persistent payload.
  • Managed software deployment, pushing an approved catalog of tools through RMM or endpoint management instead of leaving "go find and download it" as the default path for employees.
  • EDR with behavioral detection that flags an installer spawning unexpected processes or reaching out to a command-and-control server after a "normal" install finishes.
  • A standing rule to type the URL, not search for it, for any software your team downloads regularly, plus a quick internal request path so nobody feels stuck searching under time pressure.

Where this fits

  • The typosquatting post, for the lookalike-domain infrastructure that malvertising campaigns rely on to look legitimate.
  • The ClickFix post, for another attack that skips traditional malware delivery and gets the employee to do the work.
  • The EDR vs. antivirus post, for why behavioral detection catches a trojanized installer that signature scanning waves through.
  • The browser extension security post, for another everyday download decision that quietly expands what an attacker can reach.
  • The cybersecurity page, for where DNS filtering, EDR, and admin-rights policy fit into a full security program.

FAQs about malvertising

What is malvertising?

Malvertising is the practice of buying legitimate search or display ad placements and using them to point victims to a malicious page instead of the real one. The most common small business version is a sponsored search result for common software, such as PuTTY, Zoom, Notepad++, or a PDF reader, that outranks the real vendor's link and leads to a lookalike site hosting a trojanized installer. Because the ad runs through a real ad network and the landing page is often only malicious for a short window before it's taken down, it slips past reputation-based filters that would normally flag a known-bad domain.

How does malvertising get past antivirus and ad blockers?

Ad blockers filter ad content and tracking scripts, not the destination page a user is intentionally searching for and clicking through to, so a sponsored search result usually isn't blocked at all. Antivirus struggles because the downloaded file is often a legitimate installer wrapped around a malicious payload, code-signed with a stolen or cheaply purchased certificate, and distributed for only a few hours before the campaign rotates to a new domain, which is faster than many signature updates. The file frequently doesn't behave maliciously until after installation, when it quietly downloads the real payload in a second stage.

How can employees avoid malvertising when downloading software?

Skip the sponsored results entirely and click the organic listing, or better, type the vendor's known URL directly or use an internal software request process instead of searching for downloads at all. Check the URL bar carefully before downloading anything: a fake site's domain is almost always slightly off from the real one. For a business, the more reliable fix is removing the decision from the employee altogether by locking down local admin rights and pushing approved software through managed deployment instead of letting anyone download and run installers found through search.

Not sure what's stopping a fake software ad from reaching your team?

30 minutes with a DoD-cleared engineer. We'll check whether your DNS filtering blocks known malvertising infrastructure, confirm whether employees still have local admin rights they don't need, and look at whether managed software deployment could remove the risk entirely.

Book your free security assessment
Call (831) 204-0501 Book free assessment