Malicious threat actors are exploiting advertising data to launch targeted cyberattacks
Advertising data has recently posed growing cybersecurity risks as a result of its exploitation by advanced cyber threat groups, according to revelations by Kaspersky, a privacy and cybersecurity firm, during its annual Cyber Security Weekend for the Middle East, Turkiye, and Africa (META) region, with the MENA TECH team present to cover the event. While billions of ad requests are processed daily to serve personalized content, Kaspersky researchers revealed that the underlying ad infrastructure is increasingly exploited by advanced threat actors and cybercriminals for targeted intelligence gathering and cyberattacks.
The modern AdTech ecosystem relies on extensive data exchanges through multiple intermediaries to target users based on interests, browsing habits, device profiles, and approximate geolocation. Kaspersky experts warn that Advanced Persistent Threat (APT) groups abuse real-time bidding (RTB) protocols and data broker repositories to pinpoint high-value individuals and track their physical and digital movements.
Crucially, ad network vulnerabilities allow attackers to bypass traditional security perimeters and deliver sophisticated “zero-click” spyware. In these scenarios, a device can be compromised simply by loading a legitimate mobile application or website displaying an ad payload, requiring no malicious downloads or user interaction. Additionally, aggressive adware variants such as Adware.Script.Redirect continue to redirect users toward malware distribution hubs; Kaspersky blocked over 3.7 million malicious redirection attempts in the Middle East during the first half of 2026 alone.
“The advertising ecosystem was built to deliver the right message to the right person at the right time. Unfortunately, those same capabilities can be abused by sophisticated threat actors,” stated Maher Yamout, Lead Security Researcher at Kaspersky’s Global Research and Analysis Team (GReAT). “What was originally designed for commercial targeting can be transformed into intelligence gathering, allowing attackers to identify high-value individuals and deliver exploits through trusted applications. The attack surface extends well beyond traditional phishing emails”.












