Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A new form of malware delivery is making headlines, and it’s one that exploits browser vulnerabilities to evade detection. Malvertising, or malicious advertising, has long been a threat to online security. However, this latest variant takes it to a whole new level by using AI-powered techniques to break down malware into smaller pieces, then instructing the browser itself to reassemble them into an executable file.

This complex attack vector affects users of Google Chrome and Mozilla Firefox browsers, who are now at risk of downloading malware without even realizing it. The process begins when a user visits a compromised website or clicks on a malicious ad. A script is injected into their browser, which then uses AI-driven code to dissect the malware into tiny fragments, each smaller than 4KB.

These fragments are then scattered across multiple websites and domains, making them extremely difficult to detect using traditional security measures. Even more insidious is that the malware can be reassembled in real-time as it travels through the browser’s memory space. This makes it nearly impossible for even the most sophisticated antivirus software to catch.

But how does this work? In essence, the AI-powered script uses a technique called “polymorphic code” to modify its own structure and behavior constantly. This means that each time it is loaded into memory, it looks different, making it hard for security software to identify and flag as malicious. The browser itself then unwittingly becomes an accomplice in this process by being instructed to reassemble the fragments into a working executable.

The implications are severe, especially for organizations with lax security measures in place. A single infected machine can quickly spread malware throughout an entire network, leading to data breaches, system crashes, and reputational damage. Furthermore, the fact that these attacks are AI-driven means they can adapt and evolve rapidly, making them nearly impossible to keep up with.

The rise of AI-powered threats like this one highlights the urgent need for organizations to revisit their security protocols and practices. This includes implementing robust browser-based security measures, regularly updating software and plugins, and investing in more advanced threat detection tools that can keep pace with the evolving nature of these attacks. By taking proactive steps now, individuals and businesses alike can reduce their risk exposure and stay one step ahead of these sophisticated threats.

Ultimately, this latest malvertising variant serves as a stark reminder that cybersecurity is not just about patching vulnerabilities – it’s also about anticipating and adapting to new attack vectors before they become mainstream. As AI-driven threats continue to emerge, we must be prepared to respond with equal sophistication and ingenuity.


Source: The Hacker News — 2026-07-25