{"rewrite":{"id":"r_548cada70fc1357e8eef926b","clusterId":"c_88303e2c551fc7e501ffc465","slug":"youtube-paid-ads-push-malware-via-fake-tradingview-installers","model":"deepseek-v4-flash:free","headline":"YouTube Paid Ads Push Malware via Fake TradingView Installers","summary":"Security firm SafeDep reports paid YouTube video ads promising a free year of TradingView led users to fake installer sites carrying malware. The analyzed infected machine was a Mac, and compromise took about two minutes from ad click. Attackers paid Google Ads fees rather than hacking the platform.","whyItMatters":"Paid advertising on YouTube is being weaponized to distribute malware that mimics legitimate TradingView software, a tactic that is difficult to distinguish from normal software ads.","webCardHtml":"\u003cp\u003eThe attack chain starts with a video ad offering a free year of TradingView for installing a desktop app. Clicking it leads to an attacker-controlled YouTube video, whose description links to a fake TradingView site. The analyzed Mac was compromised about two minutes after the ad click at 14:16, with admin password capture and auto-run setup logged in the following minute.\u003c/p\u003e\u003cp\u003eSafeDep notes the first downloaded file is small, around 2MB, serving as a foothold rather than the full payload. The malware can receive new instructions from an attacker\u0026#39;s server, adding features that did not exist at initial installation. The macOS variant shares multiple traits with Windows malware JSCEAL or WEEVILPROXY, including communication methods and Node.js structure, though SafeDep has not confirmed a shared attack group.\u003c/p\u003e","blueskyPost":"SafeDep found the Mac compromise took two minutes from ad click. The cost structure is the detail: attackers pay Google Ads fees, so the malware ride on the platform's own monetization.","twitterPost":"SafeDep's two-minute Mac compromise shows paid ads turn Google Ads fees into malware delivery. The infection route is the platform's own monetization.","threadsPost":"SafeDep traced a TradingView ad scam to a Mac compromise that took about two minutes from click. The notable part is that attackers paid Google Ads fees, so the malware rode on the platform's own paid-ad pipeline, not on any platform breach.","newsletterBlurb":"Security firm SafeDep documents how paid YouTube ads promising a free year of TradingView route users to fake installer sites carrying macOS malware, with full compromise in about two minutes. The ad campaign was paid for through Google Ads rather than a platform hack, and the macOS variant shares traits with Windows malware JSCEAL.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260821-youtube-malware/\",\"title\":\"YouTubeの有料動画広告がマルウェア配布に悪用されていた事例をセキュリティ企業が報告\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":5651,"outputTokens":556,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1787348543,"createdAt":"2026-08-21T21:33:28.000Z","publishedAt":"2026-08-21T21:36:44.000Z","updatedAt":"2026-08-21T21:33:28.000Z"},"cluster":{"id":"c_88303e2c551fc7e501ffc465","canonicalTitle":"YouTubeの有料動画広告がマルウェア配布に悪用されていた事例をセキュリティ企業が報告","representativeArticleId":"a_8d877cfe156e18f0602f3b5b","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[\"TradingView\"],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-21T07:15:00.000Z","lastSeenAt":"2026-08-21T07:15:00.000Z","updatedAt":"2026-08-21T21:36:45.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260821-youtube-malware/","title":"YouTubeの有料動画広告がマルウェア配布に悪用されていた事例をセキュリティ企業が報告"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":["TradingView"],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
