Trusted Websites Are Becoming Malware Traps

The420.in Staff
6 Min Read

Cybercriminals are increasingly using trusted digital platforms, verified accounts, familiar software and fake security checks to spread malware, making malicious activity appear legitimate and harder for users to recognise.

How Are Trusted Platforms Being Misused?

Instead of relying only on suspicious websites or obvious scam messages, attackers are exploiting services and brands that people already recognise.

The aim is to make malicious advertisements, downloads or instructions appear to come from a trustworthy source.

One campaign involved a compromised HBO Max Reddit account authorised to run advertisements. Attackers hijacked the verified account and posted 108 malicious advertisements over about 48 hours.

The advertisements promoted fake HBO Max, fake AI and developer tools. Users who clicked them were directed to fake websites and exposed to a technique known as ClickFix, which attempted to persuade them to run malicious commands.

What Happens After a User Clicks the Ad?

The fake website may look legitimate, but instead of simply downloading a file, it can display instructions asking the user to copy a command and paste it into a system tool.

On Windows, users may be directed to tools such as PowerShell or the Run dialogue, while Mac users may be instructed to use Terminal.

The danger begins when the user executes the command. There may be no obvious suspicious download, because the command itself can trigger the malicious activity.

Such attacks can deliver information stealers, malicious loaders, cryptocurrency clippers and fake cryptocurrency wallet applications.

These tools can steal passwords, browser information, cryptocurrency-related data and other information.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Why Are Verified Accounts Being Targeted?

Attackers can use compromised verified accounts to make fraudulent advertisements appear more credible.

A verified badge, familiar logo or recognised platform can create the impression that an advertisement or software offer is genuine.

A similar campaign appeared on X in July 2026, where a sponsored advertisement from a verified account promoted a fake version of the Mac utility DynamicLake.

The campaign reportedly used malware designed to steal information and was distributed to more than 1 million ad impressions.

How Are Fake Security Checks Used?

Cybercriminals are also copying familiar CAPTCHA and human-verification pages. Users are accustomed to completing such checks, which can make the instructions seem routine.

Instead of simply asking users to prove they are human, fake verification pages may instruct them to open a system utility and paste a command. Once executed, that command can install malware.

This technique is particularly difficult to spot because the initial website itself may be legitimate. Attackers can effectively borrow the credibility of a trusted website while presenting visitors with a familiar-looking security check.

How Are Fake AI Tools Being Used?

Artificial intelligence software has also become a lure. Fake advertisements for OpenAI Codex have been used to target Mac users, with malicious software presented as a legitimate developer tool.

Users searching for popular AI services may be more willing to install software when they believe it comes from a recognised company.

In 2026, 92,000 malicious attacks disguised as AI services were detected, with fake ChatGPT applications accounting for 49 per cent. Fake Claude and Gemini applications accounted for 18 per cent each.

More than 15,000 malware samples were also identified as being disguised as agentic AI software, including trojans, spyware, exploits, downloaders, droppers and backdoors.

Also Read: https://the420.in/microsoft-warns-pipemagic-malware-chatgpt-desktop-app-ransomware/

Why Are These Attacks Harder to Recognise?

The common feature across these campaigns is the use of trust. A malicious advertisement can appear under a verified account, a fake download can imitate well-known software, and a compromised legitimate website can display what looks like an ordinary security check.

This means users can no longer judge safety only by whether a website, account or advertisement looks familiar. In some attacks, the dangerous step occurs only after the victim is persuaded to manually execute a command.

What Should Users Watch For?

Users should be particularly cautious when a website, advertisement or verification page unexpectedly asks them to copy and paste commands into PowerShell, Terminal, the Run dialogue or another system utility.

Software promoted through advertisements should also be checked carefully before installation, particularly when it claims to be a popular AI or developer tool.

A verified account, familiar brand name or professional-looking security page alone should not be treated as proof that an instruction is safe.

The420 Digital Safety Check: Trust the Platform, Verify the Command

The growing use of legitimate websites, verified accounts and familiar security screens changes what a malware trap can look like. The key warning sign may no longer be a suspicious website or strange download.

An unexpected request to run, copy or paste a system command deserves careful scrutiny, even when it appears on a platform the user already trusts.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected