Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

YouTube Paid Ads Push Malware via Fake TradingView Installers

Paid advertising on YouTube is being weaponized to distribute malware that mimics legitimate TradingView software, a tactic that is difficult to distinguish from normal software ads.

Reporting from 1 source: GIGAZINE.

YouTube Paid Ads Push Malware via Fake TradingView Installers

Security firm SafeDep reports paid YouTube video ads promising a free year of TradingView led users to fake installer sites carrying malware. The analyzed infected machine was a Mac, and compromise took about two minutes from ad click. Attackers paid Google Ads fees rather than hacking the platform.

The attack chain starts with a video ad offering a free year of TradingView for installing a desktop app. Clicking it leads to an attacker-controlled YouTube video, whose description links to a fake TradingView site. The analyzed Mac was compromised about two minutes after the ad click at 14:16, with admin password capture and auto-run setup logged in the following minute.

SafeDep notes the first downloaded file is small, around 2MB, serving as a foothold rather than the full payload. The malware can receive new instructions from an attacker's server, adding features that did not exist at initial installation. The macOS variant shares multiple traits with Windows malware JSCEAL or WEEVILPROXY, including communication methods and Node.js structure, though SafeDep has not confirmed a shared attack group.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources