It looks like just another ad tag, with a basic banner image and minimal HTML. The creative seems innocuous enough — a no-name fashion brand broadcasting new arrivals or a clearance sale. But that’s how PopCrawler infests the digital media ecosystem — appearing so boring and plain as not to set off any alarms. A virtual wallflower on the media landscape — only one with malevolent intentions. Once this prolific new phishing attack starts redirecting consumers to bogus reward sites and even tech support scams that can liquidate bank accounts, the sirens begin to blare.
Ad tags with PopCrawler phishing attacks grew 12X in June 2025.
After months of growing unique outbreaks, ad tags with PopCrawler phishing attacks grew 12X in June 2025.
While The Media Trust’s Digital Security and Operations team found a growing number of unique outbreaks across a small amount of ad tags throughout this year, this changed dramatically in June 2025. The amount of ad tags wielding PopCrawler phishing attacks exploded, growing 12.5X month over month — 200,000 malicious ad tags affecting thousands of premium publishers and adtech platforms.
A sampling of innocuous creatives that hide PopCrawler phishing attacks.
A sampling of innocuous creatives that hide PopCrawler phishing attacks.

Resilience Through Fingerprinting and Adaptive Behavior

Unlike the pervasive StringRipper phishing attack that has grown dramatically in 2025, PopCrawler’s evasion techniques are surprisingly unsophisticated. Its alarming spread can be attributed to strategic use of fingerprinting, redundancy, and adaptive behavior to bypass common security mechanisms.
Malicious payloads deployed by PopCrawler include bogus Google rewards and tech support scams.
Malicious payloads deployed by PopCrawler include bogus Google rewards and tech support scams.
The attacker’s use of multiple redirect techniques, combined with optional Base64 encoding and layered delivery methods, makes the threat particularly resilient and difficult to detect. The inclusion of fingerprinting data in the redirect URL also enables server-side filtering and targeting by the attackers. The Media Trust’s Digital Security and Operations team has assembled an in-depth report on PopCrawler’s deviously clever execution. To avoid spreading valuable information to malicious parties, it is only available by request and with a verified email. (You must submit a company email to receive the report.)
What is PopCrawler?

PopCrawler is a named phishing threat identified by The Media Trust that uses malicious advertising and sophisticated redirect chains to lead users to fraudulent phishing pages. The campaign is designed to evade traditional detection while maximizing the likelihood that users will interact with malicious content.

PopCrawler begins with a malicious advertisement that redirects users through multiple intermediary pages and deceptive pop-ups before landing on a phishing website. The campaign frequently changes its infrastructure and behavior to avoid detection by automated security systems.

PopCrawler uses techniques such as dynamic redirects, cloaking, browser fingerprinting, and conditional content delivery to hide malicious behavior from scanners while serving phishing pages only to targeted users. These tactics make the campaign significantly more difficult to identify than traditional phishing attacks. 

Cloaking is a technique that presents different content depending on who is viewing a webpage. Security scanners may see harmless content, while real users are redirected to phishing sites or other malicious destinations, making detection much more challenging.

PopCrawler affects publishers, advertisers, ad tech platforms, mobile app developers, and consumers. Publishers and advertisers risk brand damage and compromised user experiences, while consumers may be exposed to credential theft, financial fraud, or malware through phishing pages. 

The campaign abuses legitimate advertising infrastructure by embedding malicious code or redirect logic within digital ads. Because the ads can appear on trusted websites and apps, users often have no indication they are being redirected to a phishing campaign. 

Organizations should continuously monitor ad creatives and landing pages, analyze redirect behavior in real time, inspect third-party code, and deploy advanced threat detection capable of identifying malicious activity as it executes. Proactive monitoring helps stop phishing campaigns before they impact users.

PopCrawler rapidly changes domains, redirects, and attack techniques to evade static security tools. Real-time monitoring enables organizations to detect these changes quickly and block malicious campaigns before they can spread. 

Users should be cautious if they experience unexpected pop-ups, multiple redirects, requests for login credentials or payment information, unfamiliar URLs, or websites that closely imitate trusted brands while asking for sensitive information.

PopCrawler demonstrates how phishing campaigns are becoming more sophisticated by combining malvertising, dynamic redirects, and evasion techniques. Organizations can reduce risk by implementing continuous ad monitoring, strengthening digital trust and safety practices, and using real-time threat intelligence to identify and mitigate attacks before users are exposed.

PopCrawler is a sophisticated phishing campaign identified by The Media Trust that uses malicious advertising to redirect users through a series of deceptive pop-ups and intermediary pages before delivering convincing phishing websites. The campaign employs advanced evasion techniques, dynamic redirects, and cloaking to avoid detection by traditional security tools while maximizing user engagement with fraudulent content. The Media Trust’s analysis explains how PopCrawler operates, why it poses a growing threat to publishers, advertisers, and consumers, and how continuous ad monitoring and real-time threat intelligence can help stop phishing attacks before they reach users.