June was a banner month for malvertising, unfortunately, with a 2.3X rise in malicious ad tags credited to explosions in prolific phishing redirect StringRipper and just-as-bold newcomer PopCrawler. Yup, seems to be phishing season — and seniors are in threat actors’ sights, with a 3X rise month over month in malvertising targeting them. Click on each image for more details: Get four fast stats in your inbox every month by signing up for our newsletter, DTS Express.
What are the key findings from the July 2025 Fast Stats report?

The report highlights a 2.3× increase in malicious ad tags during June 2025, driven primarily by the rapid expansion of the StringRipper and PopCrawler phishing campaigns. It also underscores the growing sophistication of attacks targeting the digital advertising ecosystem.

Malvertising is the use of digital advertisements to distribute malicious content such as phishing pages, malware, scams, or deceptive redirects. Attackers abuse legitimate advertising infrastructure to reach users across websites, mobile apps, and other digital channels.

StringRipper and PopCrawler are sophisticated phishing redirect campaigns that hide malicious code within digital advertising. They use advanced obfuscation techniques to evade detection and redirect users to phishing sites or other malicious destinations.

Cybercriminals continue to exploit the complexity of the programmatic advertising supply chain, using increasingly sophisticated techniques to hide malicious code inside legitimate advertising assets and evade traditional detection methods.

Continuous ad quality monitoring helps publishers detect malicious creatives before they reach visitors, protecting users from phishing attacks, malware, scams, and disruptive experiences while preserving brand reputation and advertising revenue.

Phishing redirects send users to fraudulent websites designed to steal login credentials, financial information, or personal data. These attacks often appear legitimate, making them difficult for users to recognize until it’s too late. 

Organizations should continuously scan ad creatives, monitor runtime behavior, validate third-party code, increase visibility across the advertising supply chain, and use real-time threat intelligence to detect and block malicious campaigns before they reach consumers.

Malvertising campaigns can change rapidly, often within minutes. Real-time monitoring enables organizations to identify emerging threats quickly, remove malicious ads, and reduce the risk of phishing, malware, and other attacks impacting users.

The report is valuable for publishers, advertisers, advertising operations teams, ad tech providers, cybersecurity professionals, digital media leaders, and anyone responsible for digital advertising quality, trust, or security. 

The July 2025 findings demonstrate that malvertising continues to evolve rapidly. With phishing campaigns becoming more sophisticated and malicious ad activity increasing significantly, organizations need proactive monitoring, stronger ad quality controls, and continuous threat detection to protect users and maintain trust in the digital advertising ecosystem. 

The 4 Fast Stats — July 2025 report highlights key trends shaping the digital advertising threat landscape based on data collected by The Media Trust. The report found a 2.3× increase in malicious ad tags during June 2025, driven largely by the rapid growth of phishing redirect campaigns such as StringRipper and PopCrawler. It also examines the continued evolution of malvertising tactics, the increasing sophistication of cybercriminals targeting the advertising supply chain, and the importance of continuous ad monitoring and real-time threat detection. The findings reinforce the need for publishers, advertisers, and ad tech providers to proactively identify malicious activity before it reaches users.