It’s got to be willing ignorance at this point. Gemini Flash can easily distinguish these blatantly malicious ads from the title and redirect URL alone.
I imagine these malware ads offer very high CPCs, and I imagine Google always gets paid (ie no payment fraud). I wouldn’t be surprised if their associative payment fraud detection and banning system works orders of magnitudes better.