Cybercriminals are increasingly abusing trusted websites, verified social-media accounts, familiar software brands and fake security checks to distribute malware. Instead of relying only on obviously suspicious websites, attackers are using familiar digital environments to make malicious links and downloads appear legitimate.
A recent campaign involving a compromised verified HBO Max account on Reddit illustrates the trend. Security researchers said attackers used the account to run 108 malicious advertisements over roughly 48 hours, promoting fake streaming, AI and developer tools. Users who followed the advertisements were directed to fraudulent websites using a technique known as ClickFix.
How Trusted Platforms Are Being Abused
The basic strategy is to borrow credibility from platforms, brands or accounts that users already recognise.
In the HBO Max campaign, the compromised Reddit account was authorised to run advertisements. The malicious ads then directed users toward websites designed to resemble legitimate software or entertainment services. Researchers said the campaign targeted both Windows and macOS users.
This approach can make traditional warning signs less obvious. A familiar logo, verified account or professional-looking webpage may create an impression of legitimacy even when the content has been manipulated.
ClickFix Turns User Actions Into a Security Risk
ClickFix attacks generally rely on social engineering rather than requiring the victim to download an obviously suspicious file.
A fraudulent webpage can display a fake CAPTCHA, verification screen or software-installation process and then encourage the visitor to copy and paste text into a system utility. Security researchers have documented campaigns targeting tools such as Windows PowerShell or macOS Terminal.
The important warning sign is the unexpected instruction to execute a command. A normal website or advertisement should not require an ordinary user to run unfamiliar commands simply to verify their identity, install routine software or continue browsing.
Verified Accounts Do Not Guarantee Safe Content
The HBO Max incident demonstrates why account verification alone cannot establish that an advertisement or download is safe. Researchers reported that attackers used the compromised verified account to make malicious advertisements appear more credible. Reddit subsequently locked the account and removed the ads after being notified.
The same principle applies to software downloads. Users searching for popular applications can encounter advertisements or websites that imitate established products while distributing unrelated or malicious software.
Fake AI Tools Are Becoming a Major Malware Lure
Artificial intelligence services have also become attractive targets for impersonation campaigns.
Kaspersky reported that its security products detected more than 92,000 attacks involving malware and potentially unwanted applications disguised as AI services worldwide between January and early May 2026. Fake ChatGPT applications accounted for 49% of those detections, while fake Claude and Gemini applications each represented 18%.
Kaspersky also reported identifying more than 15,000 malware samples disguised as agentic AI software, including banking trojans, spyware, exploits and downloaders. These figures represent detections by Kaspersky's products and should not be interpreted as the total number of AI-themed malware attacks worldwide.
What Users Should Watch For
The biggest warning sign is not necessarily an unfamiliar website. It can be an unexpected request to perform a technical action.
Users should be cautious when an advertisement, website or verification page asks them to:
- copy and paste an unfamiliar command;
- open a system utility to complete a CAPTCHA or verification;
- install software from an advertisement rather than the developer's official source;
- disable security protections before installing an application; or
- provide sensitive information to a page reached through an unexpected advertisement.
A verified account, familiar brand or convincing design should not be treated as proof that an instruction is safe.
For organisations, maintaining strong access controls, monitoring suspicious advertisements and educating employees about social-engineering techniques can reduce exposure to these attacks. Regular security reviews and auditing services in india can also help businesses assess their financial and operational controls around cybersecurity risks.
Conclusion
The latest campaigns show that malware distribution is increasingly built around trust and deception rather than obviously suspicious websites. Compromised verified accounts, fake AI applications and realistic security screens can all make malicious activity appear legitimate.
The safest approach is to verify the source independently and treat unexpected requests to execute commands or install software with particular caution—even when they appear inside a familiar platform.