Duplicate » admin by request

How the Browser Delivers Malware: Drive-Bys, Bad Ads, and Fake Installers

Laptop on a desk with a cracked, fiery digital interface emerging from the screen, symbolizing cyberattack or hacking.issuing as a visual metaphor for cybersecurity breach.

Ransomware crews and data thieves have moved a lot of their delivery onto a channel that most security programs barely govern: the browser. It handles the searches, downloads, and updates that fill an ordinary workday, and attackers have learned to hide their payloads inside exactly those actions.

The appeal for them is that the user does the risky part. When someone downloads a file or runs a prompt themselves, there’s no unsolicited inbound connection for perimeter tools to flag, and the person has little reason to second-guess a step they started. Good browser-based attacks work by making the malicious thing resemble the legitimate thing the user was already after.

Drive-by downloads, malvertising, fake installers, and ClickFix prompts are the techniques doing most of this work right now. They hit different points in normal browsing, so it helps to look at how each one operates and why it slips past the defenses aimed at other attack routes.

Drive-By Downloads: Infection Without a Click

A drive-by download delivers malware when someone loads a web page, occasionally with no further interaction at all. The page runs hidden code that targets a flaw in the browser or a plugin, and the payload can install before the user notices anything unusual on screen.

Trusted sites are part of what makes this dangerous. Attackers compromise legitimate websites and plant their code there, so a page visited safely for years can serve malware on the next load. A 2025 FBI and CISA advisory reported that the Interlock ransomware group gained initial access via drive-by download from compromised sites, a method the agencies called uncommon among ransomware actors.

Many drive-bys add a nudge rather than running entirely on their own. The payload gets dressed up as something the user expects to accept, most often a browser update prompt. That same advisory documented malware disguised as fake Google Chrome and Microsoft Edge updates, turning a routine “update available” click into the moment of infection.

Patching removes a lot of the underlying flaws, though the timing tends to favor the attacker. The stretch between a browser vulnerability becoming public and a working exploit circulating has kept getting shorter, which leaves any out-of-date browser exposed the moment it reaches a hostile page.

Dark browser window with a glowing download dialog in the center, surrounded by circuit-like background lines. » admin by request

Malvertising: When the Ad Is the Attack

Malvertising delivers malware or redirects through online advertising. Ads suit attackers well because legitimate ad networks push them to large audiences, and they surface on reputable sites that lend an unearned sense of safety to whatever the ad points to.

Search ads get abused heavily. Attackers buy placements against common software queries so a malicious listing can sit at the very top of the results, dressed to look like the official download. The familiar name in the top slot carries the trust, and the page behind it returns a trojanized copy instead of the tool the searcher wanted.

The destination pages are convincing by design. Attackers replicate the real vendor’s layout, wording, and metadata, then register lookalike domains close enough to the genuine address to survive a quick glance. The click, the redirect chain, and the spoofed installer page can all pass in the few seconds it takes someone to find and download what they think is legitimate software.

Detection is tricky because the user initiates every step. They open the browser, type the query, and choose the result, so nothing in the sequence looks forced or automated. Tools watching for suspicious inbound traffic have almost nothing to catch when the file was pulled in by the person at the keyboard.

Fake Installers and Poisoned Search Results

Fake installers extend the malvertising idea into a full delivery channel. Rather than depending on a single paid ad, attackers build believable download pages for popular software and then work to place those pages wherever people go looking for the real thing.

SEO poisoning is a large part of that effort. Attackers manipulate search rankings so their malicious pages score highly for software, driver, and troubleshooting queries. One recurring method uses paired forum accounts, one posting a question and another answering with a link to a malicious archive, which lifts the poisoned result through the appearance of genuine discussion. Higher-ranked results collect the trust, and the clicks, that a buried link never would.

The choice of software to impersonate is deliberate. A 2025 campaign tied to the Rhysida ransomware group impersonated download pages for PuTTY, Microsoft Teams, and Zoom, buying search ads to place them in front of IT staff and administrators. Those users search for utilities constantly and sit among the most valuable targets, since a fake admin tool inherits the reach of whoever installed it.

A handful of details do most of the convincing:

  • Copied branding, where the page mirrors the real vendor’s design and copy closely enough to pass casual inspection
  • Lookalike domains that alter a character in a legitimate address or lean on a plausible top-level domain to seem official
  • Code-signing abuse, where the malware carries a real, sometimes short-lived, certificate so it registers as validly signed
  • Role-specific lures, with poisoned searches tuned to finance, legal, or IT so the bait fits what each group tends to look up

None of this relies on a software vulnerability. It relies on the file looking trustworthy at the point of download, which happens to be where most endpoints apply the least policy.

ClickFix: Getting the User to Run It

ClickFix drops the malicious download and gets the user to execute the payload directly. A page shows a fake CAPTCHA, a bogus error, or a “verify you’re human” step, then tells the user to copy a snippet and paste it into the Windows Run dialog or a terminal. Following the instructions runs the attacker’s command.

Its strength is disguising a hostile action as a routine fix. People have grown used to awkward verification steps and the occasional “paste this to resolve the problem” instruction, so the request rarely reads as an attack. Government responders have tracked the method in the wild, including a Russian espionage group that used fake CAPTCHAs to run PowerShell against Ukrainian targets. A newer variant called FileFix applies the same trick to a file path rather than the Run dialog.

Defending against it is awkward precisely because the user carries out the dangerous step manually. Nothing arrives as a downloaded executable for a scanner to inspect on the way in, since the payload comes as text the user runs. That sidesteps a good portion of the controls built to catch files as they land.

Awareness training reduces the odds without closing the gap. Teaching staff to distrust paste-this-command prompts helps, though the technique is built to imitate the very steps people have been conditioned to follow without much thought.

Desktop computer with a monitor; flames erupt from the pc case, signaling hardware failure or overheating. » admin by request

Governing the Browser, Not Just Scanning It

Every one of these techniques exploits the point of download rather than a single bug. A file arrives, or a command runs, in the normal course of using the browser, and most environments place little between that action and the endpoint aside from an antivirus scan after the fact. That scan can miss malware built to dodge signatures, and it never weighs whether the download should have been allowed at all.

Answering that question calls for policy at the point of download, which is the gap our newest addition to the Zero Trust Platform is being built to close. Admin By Request Web Access Management will apply rules to browsing and downloads on the endpoint itself, so the decision happens before a file reaches the user rather than after it has already run.

To see how that works and where it sits alongside your existing tools, read our breakdown of Web Access Management.

About the Author:

Picture of Pocholo Legaspi

Pocholo Legaspi

Pocholo Legaspi is a content writer at Admin By Request, where he covers privileged access management, endpoint security, threat analysis, and the wider cybersecurity issues facing IT teams. With over a decade in content marketing and SEO and a master's in business informatics, he writes about complex security topics in a way that's clear and useful for the IT teams putting them into practice.

Share this blog to your channels:

Lifetime Free Plan for 25 Endpoints,
No Strings Attached.

Fill out the form to create your account and get started.

Book a Demo

Orange admin by request circle tick logo. » admin by request