Beware of Malvertising and Tech Support Scams

Apart from email scams, cyber criminals will also make use of online advertisements (e.g. pop‑ups, banners, search ads, or social media ads) to deliver scams or malicious contents, aka “Malvertising”.  These ads often appear on legitimate websites or platforms, which makes them difficult for users to distinguish from genuine advertisements.

 

In some cases, malvertising can further lead to Tech Support Scams via:

  1. Malicious or fake ads appear in browser pop-ups, search results, or social media feeds.
  2. The ad redirects users to a fraudulent webpage posing as a system warning or security alert.
    • The fraudulent webpage displays fake error messages, often impersonating trusted branding company, e.g. Microsoft, or antivirus warnings, claiming that user’s device is infected or malfunctioning.
    • Usually, scammers will lock the browser with full-screen mode and use alarming fake message to create panic and urgency.
  3. The fake message would urge victims to:
    • call a fake support hotline,
    • key in some commands, or
    • install software for remote support access.
  4. Then, it will attempt to steal the information from the device or request the victim to pay for the fake repair or security services.

 

General Best Practices:

  1. Avoid Suspicious Links and Pop-up Ads: Never click on suspicious links or pop-up advertisements which you don’t know where it will redirect you.
  2. Update your system regularly: Keep your computer OS and software with the latest security patches.
  3. Update Antivirus software: Install and update antivirus software to detect and remove malicious files and perform virus scanning regularly.

 

If you suspect your computer is compromised with Malvertising or Tech Support Scam, please take below immediate actions:

  1. Never Response to the scammer: Do NOT response to the scammer for any action or money transfer.
  2. Isolate and contain the affected system: Disconnect the system from the network immediately.
  3. Reinstall the system from scratch: Backup your important files and reinstall your computer from scratch.
  4. Perform virus scan with the update antivirus software.
  5. Change the password immediately.
  6. Report Incident IMMEDIATELY: Report the incident to your IT support ASAP.  If there is any financial loss, report to the Police immediately. 

 

Please stay vigilant and protect your systems and information.

 

Reference:

 

 

Published on:  Feb 2026