Malvertising: fake ads that impersonate your brand
Phishing does not always arrive uninvited. Sometimes customers click an ad — one that looks like yours, at the top of a search for your own brand, leading to a clone. That is malvertising: abusing the advertising system itself to impersonate brands and distribute attacks.
How brand-ad abuse works
- Bid on your name — attackers buy ads on your brand search terms.
- Mimic your listing — the ad copies your name, wording and even your display URL style.
- Point to a clone — the click lands on a lookalike domain with a fake login or store.
- Outrank the real you — a paid slot can sit above your own organic result.
Why it is so effective
Users trust the top of the results page, and an ad on your exact brand term feels like you. The destination is often cloaked, so ad-platform checks and scanners see a clean page while real visitors get the trap. The customer did everything "right" — searched your name, clicked the top result — and still landed on a clone.
Malvertising hijacks the moment a customer is actively looking for you. The ad borrows your brand; the destination is a lookalike you can take down.
How to fight it
- Monitor search and ad platforms for ads impersonating your brand on your own terms.
- Report abusive ads through each platform's process, with evidence.
- Take down the lookalike domains the ads point to.
- Hold your own ground — maintaining paid presence on your brand terms leaves attackers less room.
Phish Plug detects the lookalike domains and cloaked pages behind malvertising and files the takedowns — so even if an ad slips through, its destination does not survive.
The takeaway
Malvertising turns the ad system against you, catching customers at the exact moment they search for your brand. You fight it on two fronts: report the impersonating ads, and remove the lookalike pages they lead to — because the destination is the part you can permanently kill.
Keep reading
Related articles
How to spot a phishing email: the red flags that matter
The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.
Read article Email security · 9 minDMARC, SPF and DKIM: stop attackers spoofing your domain
Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.
Read article Email security · 6 minEmail spoofing: how attackers fake your 'from' address
Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.
Read articleRemove the clones targeting your brand
Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.