A security company has reported instances where paid YouTube video ads were being misused to distribute malware.

Security firm SafeDep has reported that paid video ads promoting 'one year of free access to the stock charting service TradingView' were being streamed on YouTube, and users who clicked on the ads were being redirected to a fake app containing malware. While the infected device newly analyzed by SafeDep was a Mac, attacks distributing Windows malware through malicious ads impersonating TradingView and other services have been observed before.
From YouTube Ad to Root: How a Fake TradingView Installer Delivers a macOS Stealer - Real-time Open Source Software Supply Chain Security

TradingView is a service that displays price charts for stocks, cryptocurrencies, and other assets. Attackers exploited TradingView's popularity by luring users with advertisements that promised 'free access to paid features' and 'free access by installing the desktop app.' The problem with these advertisements is that they are difficult to distinguish from regular software advertisements.
According to SafeDep's investigation, on July 26, 2026, an infected device clicked a video advertisement on YouTube that claimed 'Install the desktop app and get one year of free TradingView.' The advertisement led to a YouTube video prepared by the attacker, and clicking a link in the video's description redirected users to a fake website impersonating TradingView. These advertisements were not displayed through hacking or other means, but were delivered via Google Ads after the attacker paid for the advertising.
In this case, the ad was clicked at 2:16 PM, the administrator password was obtained and the automatic execution settings were configured around 2:17 PM, meaning approximately two minutes passed between clicking the YouTube ad and the device being compromised.
The following is an overview of the attack as compiled by SafeDep. It can be seen that a YouTube video ad was placed as the initial entry point. After directing users to a fake website from the ad, a fake installer was executed, and a mechanism was installed on the Mac to download additional programs from an external server. SafeDep analyzes that the initial downloaded file was small, about 2MB, and did not contain all of the final malware, but was used as a stepping stone to later install the necessary functions.

The malware that SafeDep has analyzed in detail is for macOS, but this attack is not irrelevant to Windows users. Security firm Check Point Research
Another security firm, Bitdefender, reports that attackers, who initially focused on Facebook ads, have expanded their activities to Google Ads and YouTube. In a YouTube case confirmed by Bitdefender, compromised verified channels were repurposed to resemble official TradingView channels, displaying a large number of limited-access videos as advertisements. These videos could not be accessed through search results and required users to access them via a link or by directly entering the URL. Links to malware-infected files were included in the video descriptions, and some of these ad videos were viewed more than 180,000 times in just a few days.
The malware distributed for Windows was called JSCEAL or WEEVILPROXY, and it had functions such as obtaining cookies and passwords stored in the browser, recording keystrokes, taking screenshots, and collecting information from cryptocurrency wallets. Bitdefender has also confirmed that it has a mechanism to execute subsequent malware by adding exclusion settings to Microsoft Defender Antivirus.

The macOS version analyzed by SafeDep in 2026 also shares many characteristics with the Windows version of JSCEAL/WEEVILPROXY, including its communication method, its use of Node.js, and its use of advertisements disguised as TradingView to lure users. However, SafeDep has not definitively concluded that the macOS version was developed by the same attack group, but rather infers a high degree of correlation based on the consistency with publicly available information.
SafeDep analyzed Macs and found that after infection, the attacker could gain access to key input, screen capture, and password management features. Furthermore, because the attacker could receive and execute new commands from their server, they were able to add features that weren't present during the initial installation.
What's unique about this case is that the attackers didn't exploit vulnerabilities in the OS or browser to force an infection; instead, they combined paid YouTube ads, a TradingView page that looked like the real thing, and an installer that looked like a normal app to trick users into downloading files themselves. Bitdefender is urging users not to download apps directly from ads that advertise 'software that is normally paid but can be used for free,' but to obtain them from the official website.
Related Posts:
in Web Service, Security, Posted by log1d_ts







