Lesson 5 of 8 · 8 min read · intermediate
Browser hijackers, adware and malvertising
Some searches are made by software, not by the person at the keyboard. Learn how hijackers, adware and malvertising force searches into feeds.
Search feeds pay because a search reveals what someone wants. That only holds if the person chose where to search and what to type. Search hijacking breaks the first half of that: software on the user's device quietly changes where their searches go. The person still wants what they typed, but they never chose the search page that now earns money from them.
You ask a taxi driver for the best curry house in town. He drives you to his cousin's restaurant, where he gets a commission. You did want curry. You did eat. But the restaurant paid a finder's fee for a customer who was delivered, not persuaded, and you never agreed to the detour.
The legitimate version
It helps to start with what is allowed. Search engines pay browsers, phone makers and software companies to send them searches. A default search deal is the largest form of this. On a smaller scale, browser extension search monetisation lets the maker of a browser add-on, such as a new-tab page, earn a share when users search through it. This is a real, permitted business, provided the user was clearly told that their search settings would change, agreed to it, and can undo it easily.
Where it becomes hijacking
Permitted search extension
- Says clearly what it changes before install
- Its main purpose is the search or new-tab feature it advertises
- Changes only what it disclosed
- Removed in one step, and settings return to normal
- Sends the user's own query unaltered
Browser hijacker
- Presents itself as something else: a PDF tool, a map, a game
- Changes the default search or home page without clear consent
- Routes queries through extra servers before showing results
- Hard to remove, or re-installs itself
- May add, replace or alter queries and ads
A browser hijacker earns from the same feeds as legitimate extensions, which is exactly why it is damaging: its searches are mixed in with honest ones. The user's intent is often genuine, so conversion rates may not look terrible. The breach is consent.
Adware: making searches and clicks the user never made
Adware goes further. Once installed, usually bundled with free software, it can insert extra ads into pages, replace the ads a search engine showed with its own, or generate searches and clicks in the background with no human involved at all. Background searches are a form of query fraud, and background clicks are plain click fraud. When adware claims credit for a visit or purchase that would have happened anyway, it overlaps with cookie stuffing.
Microsoft documented a clear example in December 2020. It described a malware family it called Adrozek, which modified browsers including Chrome, Edge and Firefox to inject extra ads into search results pages. Microsoft said that at its peak in August 2020 the threat was observed on more than 30,000 devices a day, and that the operators earned through affiliate programmes that paid for traffic referred to certain pages.
Malvertising: the delivery route
Malvertising means using advertising itself to spread harmful software or scams. An ad, sometimes placed through a normal ad network, leads to a fake "update your browser" page or a bogus download. The user installs it and now has a hijacker or adware. Malvertising also includes forced redirects, where an ad's code sends a visitor to another site without a click. Those forced visits are sometimes sold onward as traffic, which connects this lesson back to traffic laundering.
So the pieces fit together as a loop: malvertising installs the software, the software hijacks searches or fabricates clicks, and a search feed, unknowingly, pays for them.
Who pays and who is hurt
- The user loses control of their browser, sees worse results, and is exposed to further scams because someone else now controls their traffic.
- The advertiser pays for clicks on ads that were inserted or forced, and sometimes pays twice when a genuine click is intercepted.
- The search engine and feed provider unknowingly pay out a revenue share, then have to recover it.
- Honest extension publishers face tighter rules and suspicion because of the dishonest ones.
Red flags in feed data
- Searches arriving from a "source" that is a single extension or toolbar ID with a very large and sudden user base.
- Queries that look machine-made: identical strings, odd formatting, or terms unrelated to each other from the same user in seconds.
- Navigational queries, such as brand names, arriving in bulk. These suggest people who meant to go somewhere else.
- High search volume with very little engagement afterwards, or ad clicks with no dwell time on the advertiser's site.
- User complaints or store reviews saying "this changed my search engine and I cannot remove it".
Key takeaways
- Search hijacking redirects a user's searches to a monetised feed without clear consent; the intent may be real but the choice was not.
- Adware can inject or replace ads and generate searches and clicks with no human action.
- Malvertising is the delivery route: ads that lead people to install the software or that force redirects.
- Legitimate extension monetisation depends on clear disclosure, consent, a matching main purpose and easy removal.
- Bulk navigational queries, machine-like query strings and sudden single-source volume are the tell-tale signs.
Questions people ask
What is a browser hijacker?
A browser hijacker is software, often a browser extension, that changes your default search engine, home page or new-tab page without clear permission, and is hard to undo. Its operators earn a share of the advertising shown on the searches it redirects. Legitimate search extensions do the same thing openly, with disclosure, consent and one-step removal.
How do search hijackers make money?
They route your searches to a results page that carries a syndicated search feed. When you click a sponsored result, the advertiser pays the search engine, which shares revenue with the feed partner, who shares it with the hijacker's operator. Some also insert extra ads or generate searches in the background, which is outright click fraud.
What is the difference between adware and malvertising?
Malvertising is the use of online ads to spread harmful software or scams, or to force redirects. Adware is software on a device that shows, inserts or clicks ads without the user's real consent. They often work together: a malicious ad persuades someone to install a program, and that program is the adware that then hijacks searches or fakes clicks.
Are search extensions legal?
Yes, when they are honest. An extension may offer a search or new-tab feature and earn from the searches, as long as it clearly discloses the change, gets consent, does what it claims, and can be removed easily. Secretly changing search settings or misdescribing the product breaches browser store rules and feed policies, and can break consumer-protection law.