AdSecure Releases Report on 'Malvertiser' Activity During Pandemic

AdSecure Releases Report on 'Malvertiser' Activity During Pandemic

DUBLIN — AdSecure has released a report concerning trends in malicious online activity during the COVID-19 pandemic.

The company monitored malicious activity from March 1 to April 15, 2020 to see how the COVID-19 health crisis was being exploited by bad actors.

“As millions of people are now working from home, where online security isn’t as stringent compared to office cybersecurity systems, the pandemic has created a perfect storm for malvertisers,” the report begins.

AdSecure concluded that malicious attacks grew exponentially alongside lockdowns and hit a peak of +116.14% on March 18.

This is the rest of AdSecure's report on “malvertisers”:

As lockdowns began to be introduced across the globe, the number of attacks increased dramatically.

The blue line represents the percentage rate of malvertising attacks based on comparing daily data with the number of attacks on March 1, and the red line represents the trend analysis.

We observed an increase in threats worldwide, particularly in the digital advertising ecosystems of prized “Tier 1” GEOs. Though subsiding somewhat from the massive spikes in late March, threat levels remain strong through the first half of April, with a more consistent, sustained pattern of attack, remaining significantly higher than levels detected during the first half of March.

Malvertiser’s Weapons of Choice

Malvertisers are using well-known logos — including the World Health Organization logo — to fool users into clicking on malware ads.

When analysing data on threat levels, we identified specific increases in the deployment of 4 types of malvertising attacks: Adware, Malware, Phishing Scams, and a very heavy use of Scareware attacks.

Many of these attacks made use of major branding that would be instantly familiar to their intended targets — phishing attacks leveraging fake Walmart offers in the US, Intermarche in France, and Amazon in multiple countries.

With the terms “Coronavirus”, “COVID-19”, and WHO (Word Health Organization) in the news constantly, malvertisers are using them to manipulate users, playing on their fears and anxieties to get them engaged with bad ads containing Malware.

In the example below, AdSecure found a mobile banner ad in Italian, one of the countries worst hit by the pandemic. The ad delivers Malware via an auto-download, using the logo of the World Health Organization (WHO) and the GooglePlay logo to imply legitimacy.

The text translates to: “Ways to get rid of Coronavirus. Download the life-saving form here to stop this global pandemic.”

However, the text is not grammatically correct in Italian, so was obviously translated from another language — through Google Translate perhaps — so hopefully that deterred some end users from clicking on the banner ad.

Scareware Has Been the Preferred Choice of the Cybercriminal

Above all, the favourite attack delivery method during this spike in malicious activity appears to be Scareware, fake alerts claiming an imminent or existing threat to a user’s device — which of course does not exist — and is designed to trick the user for falling into a scam.

Scareware attacks grew exponentially, if we take the data from March 1 as the control, by March 4 there was a 485% increase by March 6 a 2,628% increase and by March 8 a 3,342% increase, where it remained at this new high right through to April 15.

While the style and tone of Scareware attacks can vary, we often see these take the form of a tech support scam, wherein users are alerted that their system is infected with certain types of virus, or spyware.

Again, cybercriminals often rely on the iconography of well-known brands to imply legitimacy, convince users that they will indeed be contacting Microsoft technical support, as seen in the examples below:


Of course, the user isn’t contacting Microsoft, they’re falling into a trap.


Bad Ads Surged Globally, but the U.S. Got Hit Particularly Hard

AdSecure examined which were the top 5 GEOs that received the highest malvertising attacks:

Tier 1 GEOs faced a wave of attacks with malvertisers heavily targeting the United States, with detected threats in the U.S. nearly 3x higher than in the other top 4 GEOs.


Windows PCs and iPhones Were Among Malvertisers’ Top 5 Device Choices

Windows laptops and PCs came out on top as malvertisers attacked users working from home. For Apple users, the iPhone 8 and iPhoneX were top of the cybercriminal devices to attack.

AdSecure’s Sales Manager Bryan Taylor commented, “There isn’t much safety to be found in any particular device and browser combination, either, as throughout March and April we can see that threats are being detected consistently across multiple devices and browsers.”

With more people frequently browsing on both their desktop and mobile devices and using multiple browser options, Taylor added, “malvertisers can spread their attacks accordingly, maximizing the effective impact of each bad ad campaign they are running.”

“With this sustained increase in malicious activity within the digital advertising ecosystem,” Taylor continued, “it’s likely that as social distancing measures, and lockdowns continue while the world get’s a collective handle on the COVID-19 crisis, cybercriminals will continue to take advantage of the situation by deploying malicious ads, and it is vital that the industry remain vigilant in the fight against malvertising, particularly during the unprecedented times we all find ourselves in.”

“AdSecure is here to help publishers and ad platforms with the challenge of fighting malicious and poor quality ads while maintaining user safety and experience,” said a rep. “Our free trial account is available to anyone looking to #StopBadAds.”

To learn more, reach AdSecure at contact@adsecure.com.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Australian eSafety Commissioner Demands Stricter Child Protection Codes

Australia’s online safety regulator, eSafety, is once again reviewing a “final” draft of industry codes to protect children from pornography and other age-inappropriate content, after eSafety Commissioner Julie Inman Grant rejected the previously announced “final” codes as insufficiently stringent.

Liz Flynt Debuts 'Hustler: 50 Years of Freedom' Book

Liz Flynt has released her new retrospective book, “Hustler: 50 Years of Freedom.”

Nerdgasm: A Look at the Naughty Side of Pop Culture Geekdom

From “Call of Duty” to cosplay, from tabletop dice rolls to dungeon-inspired dirty talk, the worlds of geek fandom and fantasy are no longer confined to the basement. They’ve kicked down the door, shed the “Firefly” tee and gone full frontal.

Kyrgyzstan Parliament Moves to Outlaw Internet Pornography

A parliamentary committee of the Supreme Council of Kyrgyzstan on Tuesday approved a measure to outlaw online adult content in the country.

Sweden Bans Purchase of 'Remote' Sexual Services

The Riksdag, Sweden’s parliament, has approved a proposal to criminalize purchasing sexual services performed remotely by streamers and custom content creators.

Asa Akira to Deliver XBIZ Talk at Miami Conference

XBIZ is pleased to announce that decorated performer, Pornhub brand ambassador, and author Asa Akira is set to deliver an exclusive talk at XBIZ Miami.

JustFor.fans Launches 'Fentanyl Test Strip' Initiative

JustFor.fans (JFF) has launched a test strip initiative to combat the nationwide fentanyl crisis.

2025 XBIZ Miami Speaker Lineup Announced

XBIZ is pleased to announce the release of the full speaker lineup for XBIZ Miami, the latest edition of the adult industry’s premier summer conference, set to take place May 19-22 at the Nautilus Sonesta Miami Beach hotel in South Beach.

AV Bulletin: Arizona's About-Face, What New Laws Mean for Adult

Industry stakeholders and free speech advocates have anxiously been awaiting the Supreme Court’s decision in Free Speech Coalition v. Paxton, which could significantly impact state age verification laws around the United States. In the meantime, state legislatures continue to weigh and pass AV bills, the U.K. and the EU are moving ahead with their own AV mandates and strategies, and legal challenges continue to play out in U.S. courts — with some cases on hold pending the SCOTUS ruling in Paxton.

Million Billion Media Launches New Website

Management and PR agency Million Billion Media (MBM) has launched a new website.

Show More