The Media Trust’s Malware Desk identified a sophisticated malvertising campaign we’ve named DarkRelay, a cloaked redirector designed to evade detection, break out of sandboxed advertising environments, and drive real users to fraudulent antivirus offers.
What makes DarkRelay noteworthy is not the scam at the end of the chain. It is the combination of techniques the campaign uses to make sure security tools have difficulty seeing what actual users experience.
DarkRelay begins with what appears to be an ordinary ad impression on a publisher page. A legitimate-looking creative contains an attacker-controlled script that connects the ad environment to a cloaked Traffic Distribution System (TDS).
Before exposing its malicious behavior, DarkRelay fingerprints the visitor’s browser and environment. It looks for signals that help distinguish a real person from automated security tools, including browser characteristics, device information, automation indicators, screen properties, and other environmental data.
The server then makes a decision.
If the visitor appears to be a scanner or bot, DarkRelay can return harmless content that resembles ordinary analytics or viewability tracking. If the visitor passes its checks, the same infrastructure can instead deliver the malicious redirect sequence.
That ability to show different behavior to different visitors is an important part of the threat. A security scan can encounter DarkRelay and see nothing obviously malicious, while a consumer encountering the same campaign receives an entirely different experience.
Once DarkRelay selects a target, persistence becomes its defining characteristic.
Malicious ads frequently operate inside sandboxed iframes designed to restrict what an ad can do within the surrounding webpage. Instead of relying on one method to escape those restrictions, DarkRelay attempts 12 different navigation techniques, ranging from direct top-window redirects to hidden links, forms, new windows, meta refreshes, and other browser behaviors.
If all 12 attempts fail, DarkRelay has another option waiting: it can hijack the visitor’s next legitimate click or tap and use that interaction to trigger the redirect. In other words, DarkRelay does not treat a blocked redirect as the end of an attack. It simply tries another route.
When the redirect succeeds, the victim is routed through an affiliate redirector to a fake antivirus page personalized with information about the visitor’s device.
The page uses familiar social-engineering tactics: fake security scans, fabricated threats, countdown timers, alarming sounds, fullscreen experiences, and a scripted “AI” assistant. The objective is to convince the victim that their device has been compromised and urgently needs antivirus protection.
The final offer may even lead to legitimate antivirus software. The fraud lies in how the purchase is generated. The attacker frightens the consumer into buying through an affiliate link, allowing the campaign operator to potentially collect a commission from a sale created through deception.
DarkRelay demonstrates why sophisticated malvertising cannot always be identified through domain lists, individual redirects, or conventional automated scanning. The campaign is designed specifically to manipulate what security systems see.
Detecting threats like DarkRelay requires examining the entire behavioral chain under realistic conditions: how a creative loads, how the environment is fingerprinted, how responses change between visitors, and what happens when the ad attempts multiple methods of escaping its sandbox.
The Media Trust’s Malware Desk identified DarkRelay because our approach looks beyond individual indicators to the sequence of behaviors that reveals malicious intent.
For publishers and advertising platforms, that distinction matters. A scan that appears clean does not necessarily mean an ad experience is safe. DarkRelay was engineered around that assumption.
DarkRelay is a sophisticated malvertising campaign identified by The Media Trust’s Malware Desk that uses browser fingerprinting, server-side cloaking, and multiple redirect techniques to evade security tools. The campaign can distinguish automated scanners from real users, serve harmless content when it detects security systems, and deploy 12 methods to escape sandboxed ad environments. Successful redirects lead consumers to personalized fake antivirus experiences designed to generate affiliate sales through deception.
DarkRelay is a sophisticated malvertising campaign identified by The Media Trust’s Malware Desk. It uses browser fingerprinting, server-side cloaking, and multiple redirect techniques to evade detection and redirect real users to fraudulent antivirus offers.
DarkRelay fingerprints a visitor’s browser and environment to help determine whether it is interacting with a real person or an automated security tool. Suspected scanners can receive harmless-looking content, while real users may receive the malicious redirect sequence.
DarkRelay attempts 12 different navigation techniques to break out of sandboxed iframes. If those attempts fail, it can hijack the user’s next legitimate click or tap to trigger the redirect.
DarkRelay is designed to manipulate what security systems see. Detecting it requires examining the full behavioral chain, including how the creative loads, how visitors are fingerprinted, how responses change, and how the campaign attempts to escape its sandbox.
The Media Trust was the first to detect this new malvertising campaign and has a full technical brief available for download here.