Skip to main content
← All Articles

Tag

#Malvertising

16 articles

Advertisement

Vidar Stealer & XMRig Campaign Leverages Malvertising, AMSI Bypass
HIGH
Malware

Vidar Stealer & XMRig Campaign Leverages Malvertising, AMSI Bypass

Financially motivated campaign delivers Vidar stealer and XMRig miner via malvertising for cracked software, targeting consumers and SMBs globally.

Runtime Rebel Intel
5 min read · Aug 9, 2026
DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft
HIGH
Threat Intel

DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft

North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.

Runtime Rebel Intel
3 min read · Jul 30, 2026
SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly
HIGH
Malware

SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly

The SourTrade malvertising operation bypasses security controls by using the victim's browser to assemble malicious Bun runtime executables in real-time.

Runtime Rebel Intel
4 min read · Jul 25, 2026
HIGH
Malware

Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware

A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
HIGH
Malware

Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software

A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…

Runtime Rebel Intel
5 min read · Jul 8, 2026
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
HIGH
Malware

OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware

Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.

Runtime Rebel Intel
3 min read · Jun 22, 2026

Advertisement

Operation FlutterBridge: New FlutterShell Backdoor Targets macOS
HIGH
Threat Intel

Operation FlutterBridge: New FlutterShell Backdoor Targets macOS

Researchers discover Operation FlutterBridge, a malvertising campaign delivering the FlutterShell backdoor to macOS users via Google and YouTube ads.

Runtime Rebel Intel
3 min read · Jun 4, 2026
DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
HIGH
Threat Intel

DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware

DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…

Runtime Rebel Intel
4 min read · Jun 2, 2026
Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests
MEDIUM
Malware

Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests

Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.

Runtime Rebel Intel
4 min read · May 19, 2026
HIGH
Threat Intel

Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware

Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.

Runtime Rebel Intel
3 min read · May 10, 2026
HIGH
Malware

MacSync Stealer Distributed via Malicious Homebrew Ad Campaign

Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.

Runtime Rebel Intel
4 min read · May 1, 2026
INFO
Threat Intel

Google Deploys Gemini AI to Combat Malvertising and Brand Fraud

Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.

Runtime Rebel Intel
3 min read · Apr 16, 2026
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
HIGH
Malware

Mirax Android RAT: Bypassing Security via Malicious Meta Ads

Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.

Runtime Rebel Intel
3 min read · Apr 14, 2026
AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion
MEDIUM
Threat Intel

AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion

Security researchers have identified a sophisticated AitM phishing campaign using Cloudflare Turnstile to hijack TikTok for Business accounts for malvertising.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions
HIGH
Threat Intel

Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions

U.S. taxpayers targeted by malvertising campaign delivering ScreenConnect and HwAudKiller to disable security software via vulnerable Huawei drivers.

Runtime Rebel Intel
4 min read · Mar 24, 2026
InstallFix Attacks: Malvertising Spreads Fake Claude AI Code
HIGH
Threat Intel

InstallFix Attacks: Malvertising Spreads Fake Claude AI Code

InstallFix attacks leverage malvertising and ClickFix-style techniques to spread fake Claude AI code, targeting users of coding assistants and CLI operations.

Runtime Rebel Intel
5 min read · Mar 10, 2026