At its annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky talked about the risks that advertising data can pose. While the digital advertising ecosystem has become an essential part of today's internet, enabling businesses to reach the right audiences with relevant content, every day, billions of advertising requests are processed behind the scenes to deliver personalized experiences across websites and mobile applications. According to Kaspersky experts, the same infrastructure that powers targeted advertising can also be exploited by advanced threat actors to identify, track and compromise carefully selected victims.
Advertising technology, or AdTech, is designed to help advertisers reach users based on characteristics such as their interests, browsing habits, device information and approximate location. While this ecosystem serves legitimate commercial purposes, it also relies on the collection and exchange of vast amounts of user data through multiple intermediaries. Kaspersky researchers warn that the same information used to deliver advertisements is being used to provide valuable intelligence for cybercriminals and advanced persistent threat (APT) groups. By abusing advertising platforms, real-time bidding (RTB) systems and data broker ecosystems, attackers can identify specific individuals, monitor their movements and, in some cases, deliver highly targeted "zero-click" spyware that require no interaction beyond opening a legitimate application displaying advertisements.
While most adware is largely seen as a privacy risk by collecting user data, some adware variants such as Adware.Script.Redirect can be used by threat actors to redirect users to malicious websites that distribute malware. In the Middle East region alone, Kaspersky in H1 2026 blocked more than 3.7 million attempts to redirect users to malicious content in the first half of the year.
"The advertising ecosystem was built to deliver the right message to the right person at the right time. Unfortunately, those same capabilities can be abused by sophisticated threat actors," said Maher Yamout, Lead Security Researcher at the Global Research and Analysis team at Kaspersky. "What was originally designed for commercial targeting can be transformed into intelligence gathering, allowing attackers to identify high-value individuals, understand their behavior and deliver exploits through trusted applications and websites. As advertising platforms become more precise, organizations must recognize that the attack surface extends well beyond traditional phishing emails and malicious downloads."
To reduce the risk of ad-tech-enabled surveillance and targeted attacks, Kaspersky recommends that consumers install a trusted cybersecurity solution such as Kaspersky Premium, capable of detecting malicious activity, and keep their devices and applications updated. Organizations, meanwhile, should adopt a layered security strategy by deploying Endpoint Detection and Response (EDR) solutions such as Kaspersky NEXT EDR, implementing a dedicated anti-targeted attack platform such as Kaspersky Anti Targeted Attack (KATA), and leveraging Kaspersky Threat Intelligence to identify emerging attacker infrastructure, tactics, techniques and procedures (TTPs). Combined with regular reviews of application permissions and the deployment of ad blockers across corporate devices to minimize exposure to advertising infrastructure, these measures can help limit organizations' exposure to ad-tech-enabled surveillance and targeted attacks.








