Hijacking
Malvertising and forced redirects
A malicious ad or script sends the visitor to another page without a click, sometimes to a feed page, sometimes to a scam.
How it works
Malvertising is advertising used as a delivery vehicle for something harmful. One common form is the forced redirect: the user is reading a page when an ad's code takes over the tab and loads a different site. No choice was made and often the "back" button does not work.
Search arbitrage meets this in two ways. As a victim: forced redirects can be sold to an arbitrageur as "redirect" or "pop" traffic, and visitors who arrive unwillingly make poor, complaint-prone traffic. And as a channel for abuse: a feed page loaded by a forced redirect records a visit, and sometimes a click, that no person intended.
Who pays for it
Users, who may be led to scams or malware. Publishers whose sites carried the bad ad and lose readers. Advertisers paying for unwilling visitors. The arbitrageur, when the feed finds the source.
Who does it, and why
Malicious advertisers buying cheap display inventory to harvest redirects, and traffic resellers who ask no questions about where redirects come from.
Warning signs
- Visitors arriving with no click on any ad you placed.
- Extremely short sessions and high rates of immediate tab closure.
- Mobile users complaining that a site "sent them" to your page.
- Traffic from ad networks known for pop and redirect inventory.
Defences
- Buy only click-initiated traffic for feed pages and say so in insertion orders.
- Publishers can protect their own sites with ad-quality scanning; ClearTrust's PubTrust is one such product.
- Monitor engagement before the ad click to confirm the visitor chose to stay.
- Cut any source that generates user complaints about forced navigation.
An example
Real case: the DNSChanger operation, shut down in 2011, went beyond ads to the network level. Malware changed victims' DNS settings so that clicks on search results and ads were redirected to sites that paid the gang. US authorities said more than 4 million computers were infected and at least $14 million was earned.
Documented cases
- DNSChanger (Operation Ghost Click) (2011): Malware that hijacked search-result clicks and swapped ads on infected computers
- Adrozek (2020): Browser-modifying malware that injected extra ads into search results
- Malicious "direct search" redirects on parked domains (2025): Zero-click parking abuse: visitors to parked and typo domains sold on to scams and malware