A sophisticated cybercriminal campaign has significantly expanded its reach by leveraging Google Ads and YouTube to distribute malware disguised as free access to TradingView Premium, a popular financial trading analysis service. Security researchers from Bitdefender Labs have tracked this operation for over a year, noting its evolution from initially exploiting Facebook Ads to now targeting a broader audience through Google’s advertising ecosystem and YouTube. The attackers employ highly organized tactics, utilizing more than 500 unique website addresses and deploying thousands of malicious ads daily in multiple languages, including English, Vietnamese, and Thai. To enhance credibility and evade detection, the threat actors hijack legitimate, verified business accounts on Google and YouTube, such as a Norwegian design agency’s Google advertiser account. They also compromise verified YouTube channels, erasing original content and rebranding them to closely mimic the official TradingView channel, complete with authentic logos, banners, and mirrored playlists. These fake channels use unlisted videos, which are promoted through paid ads, to lure victims with promises of secret methods for obtaining TradingView Premium for free. One such video amassed over 182,000 views in just a few days, demonstrating the campaign’s aggressive reach. Users who click on these ads are redirected to malware-laden downloads designed to steal credentials and compromise accounts. The campaign’s expansion to Google and YouTube exposes a much larger pool of content creators and regular users to credential theft and account compromise. The use of hijacked, verified accounts and sophisticated impersonation techniques makes the scam particularly convincing and difficult for users to detect. Researchers emphasize that the campaign’s persistence and adaptability, including its ability to quickly shift platforms and tactics, pose a significant threat to the financial and personal security of targeted individuals. The operation’s global scale and multilingual approach indicate a well-resourced and coordinated threat actor. Security experts recommend heightened vigilance, especially when encountering offers for free premium services through ads, and urge platforms to strengthen verification and monitoring processes to prevent account hijacking. The campaign’s technical sophistication, including the abuse of advertising infrastructure and social engineering, highlights ongoing challenges in combating malvertising and credential theft. Organizations and individuals are advised to verify the authenticity of offers and channels before engaging with advertised content. The incident underscores the need for continuous monitoring of advertising platforms for signs of compromise and malicious activity. Bitdefender’s ongoing research into the campaign provides valuable insights into the evolving tactics of cybercriminals targeting the financial sector. The expansion of this scam to major platforms like Google and YouTube marks a significant escalation in the threat landscape for both content creators and everyday users.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Hexastrike reported an active Reddit-based campaign using fake free TradingView Premium offers across at least five subreddits to deliver Vidar infostealer to Windows users and AMOS stealer to macOS users. The operation used aged or compromised Reddit accounts, compromised business websites for payload hosting, and rapidly rotated domains to evade detection.
Follow-on coverage highlighted that Google Ads were being used to deliver a trojan masquerading as TradingView Premium, reinforcing the cross-platform nature of the campaign. The reporting did not indicate a separate incident, but added technical clarity on the malware delivery method.
Researchers reported that the same 'TradingView Premium' malware scam had moved beyond Meta and was being distributed through Google Ads and YouTube. This marked an escalation in the campaign's reach across major advertising and content platforms.
A malware campaign using fake 'TradingView Premium' offers was already active on Meta platforms before later expanding elsewhere. The scam used malicious ads to lure users into downloading a trojanized file disguised as premium trading software.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcetechradar.com
Open sourcehackread.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.