As extreme temperatures scalded the US and other parts of the globe in June, a highly evasive malvertising threat was bringing the heat to the digital media ecosystem. StringRipper phishing redirects exploded in June 2025, growing 15X month over month and becoming one of the most prolific attacks ever identified by The Media Trust. StringRipper poses a dire and evolving threat across the digital advertising ecosystem, impacting consumers, adtech platforms, and digital media companies alike. This malvertising is particularly insidious because it infects existing, legitimate ad tags, making malicious ads appear perfectly benign even under scrutiny.

It employs advanced obfuscation, dynamic function creation, and randomized timing to mimic genuine user interactions, making it exceptionally challenging for automated systems to detect. Its sophisticated multi-stage process and environment fingerprinting allow it to avoid security checks and disable tracking mechanisms by overriding critical global properties such as XMLHttpRequest and fetch. Ultimately, users are redirected to fake virus alerts — often spoofing trusted brands like McAfee — which trick them into downloading malware or revealing personal information.
StringRipper Phishing Attack
The latest malicious payload leveraged in the StringRipper phishing attack, seen across thousands of premium publishers and adtech platforms in June 2025.
Thousands of premium publishers and adtech platforms are fighting back against this pernicious threat daily. While at the beginning of 2025, StringRipper was being spread primarily by one DSP with a very large footprint; now it’s being delivereer  in numerous  The Media Trust has developed new techniques on the fly to identify this dreadful evolution in phishing delivery, while also employing advanced real-time mechanisms on publisher pages to halt redirects before they activate.

In-Depth Analysis

The Media Trust’s Digital Security and Operations team has assembled an in-depth report on StringRipper’s complicated execution. To avoid spreading valuable information to malicious parties, it is only available by request and with a verified email. (You must submit a company email to receive the report.)
What is StringRipper? 

StringRipper is a sophisticated phishing and malvertising campaign that compromises legitimate advertising tags with hidden malicious code. The attack redirects users to scareware, fake antivirus alerts, phishing pages, and other fraudulent destinations while appearing to originate from trusted advertising campaigns. 

The Media Trust observed a 15× increase in malicious ad tags carrying StringRipper during June 2025 as the campaign spread beyond a single DSP into multiple advertising platforms. This broader distribution significantly increased its reach across premium publishers and digital advertising environments.  

StringRipper inserts a small amount of heavily obfuscated JavaScript into legitimate ad tags. That code serves as a launcher for externally hosted malicious payloads, which perform browser fingerprinting, generate dynamic redirects, and send users to phishing or scareware websites while avoiding detection. 

StringRipper uses advanced obfuscation, dynamic function creation, randomized execution timing, browser fingerprinting, and externally hosted payloads to disguise its behavior. These techniques allow it to mimic legitimate user interactions and bypass many traditional scanning and security tools.

StringRipper commonly delivers phishing pages, fake antivirus alerts, scareware, tech support scams, deceptive browser warnings, and other malicious redirects designed to steal credentials, install malware, or trick users into making fraudulent payments.

The campaign impacts publishers, advertisers, ad exchanges, DSPs, SSPs, ad tech providers, and consumers. Organizations face risks including compromised ad quality, brand damage, and lost revenue, while users may be exposed to phishing attacks, malware, and credential theft.

Organizations should continuously monitor ad tags and creatives, inspect third-party JavaScript, analyze runtime behavior, identify obfuscated code, and share threat intelligence across the advertising supply chain. Real-time monitoring is essential because StringRipper evolves rapidly to evade detection.  

Browser fingerprinting allows attackers to determine whether a visitor is a real user or an automated security scanner. By selectively delivering malicious payloads only to targeted users, StringRipper reduces the likelihood that its attacks will be detected during automated inspections. 

StringRipper frequently changes its payloads, redirect infrastructure, and execution methods. Continuous, real-time monitoring enables organizations to detect malicious behavior as it occurs and stop attacks before users are redirected to phishing or scam websites.  

The rapid expansion of StringRipper demonstrates how quickly modern malvertising campaigns can scale across the digital advertising ecosystem. Organizations need proactive ad quality monitoring, advanced threat detection, and continuous supply chain visibility to protect users, preserve brand trust, and defend against increasingly sophisticated phishing attacks. 

StringRipper is one of the fastest-growing phishing campaigns targeting the digital advertising ecosystem. In June 2025, The Media Trust observed a 15× increase in malicious ad tags carrying the attack as it expanded beyond a single demand-side platform (DSP) into multiple advertising channels. StringRipper infects legitimate ad tags with highly obfuscated code that redirects users to scareware, fake antivirus alerts, phishing pages, and other fraudulent destinations while evading traditional security tools. The campaign leverages dynamic code generation, browser fingerprinting, randomized execution, and external payloads to remain difficult to detect. The Media Trust’s analysis explains how StringRipper has evolved, why it poses a growing threat to publishers, advertisers, and consumers, and what organizations can do to mitigate these increasingly sophisticated malvertising attacks.