Copy article

Your Computer Might Be Working for Criminals Right Now And a YouTube Tutorial Helped It Happen

ended 12. February 2026

This is the dark side of the automation boom. It is not just about dodgy advice online. It is about how easily "helpful" content is being weaponised to turn your PC into a tool for organised crime.

The Bait and Switch

Security experts, Malwarebytes reports a fake version of the popular 7-Zip file archiver has been silently converting home computers into proxy nodes for cybercriminals. The infection chain started with YouTube tutorials pointing viewers to the wrong website. Malwarebytes revealed this week that users were directed away from the legitimate site 7-zip.org to the lookalike site 7zip.com which delivered a fully functional installer with hidden malware that enrolls your PC into a bot network. The bot uses your internet connection for fraud, data scraping, and identity laundering without your knowledge.

The Content Trap

This is not an isolated case. Google's Threat Intelligence Group disrupted what it called the world's largest residential proxy network in January 2026, finding over 550 threat groups, including state backed operations from China, Russia, Iran and North Korea, routing attacks through ordinary people's home connections. When the unaware trust a quick video tutorial, they are opening the door to disaster. 

The pattern is chilling: attackers are not exploiting software vulnerabilities. They are exploiting human trust, in familiar respected brand names, helpful tutorials, and downloads that look exactly like the real thing. 

We'd like your views:

  • Have we built a digital world where nobody can tell genuine from fake?
  • Should YouTube and other platforms bear responsibility when their content becomes an unwitting malware distribution channel?
  • How should businesses protect non-technical staff who download everyday tools without knowing which domain is legitimate?
  • Is "just be more careful online" an acceptable defence when state backed criminals are designing pixel-perfect deceptions?
  • What does this tell us about the hidden cost of the "free software" ecosystem and who should be funding its protection?

4 responses from the Newspage community

Copy all

Star Quote
Copy

Platform moderation is a joke with a punchline nobody is laughing at. YouTube can punish a creator for a dodgy thumbnail in hours, but tutorials actively funnelling viewers to malware sites stay up for weeks. The pattern is always the same: lightning fast at catching innocent transgressions, glacially slow at stopping serial criminal exploitation. If your algorithm can detect a copyright claim in seconds, it can flag links to malicious domains. Big tech must choose to.

For businesses, stop asking non-technical staff to be cybersecurity experts. They are not. Lock down machines so users cannot install software without approval. Use a standard build so any compromised PC can be wiped and rebuilt in minutes, not days. The answer is not more training videos about phishing. It's architecture that assumes people will click the wrong thing, because they will, and limits the blast radius when they do. That's not treating your team like children. That is treating the threat like an adult.
Copy

We’ve built a world where fake looks real. That’s not an accident, it’s the business model. This 7-Zip scam started with “helpful” YouTube tutorials sending people to a lookalike site, then a legit-looking installer quietly turned PCs into proxy nodes for organised crime. Your internet becomes their getaway car. So no, “just be more careful” isn’t a strategy when criminals are running pixel-perfect cons. Small businesses: lock it down. No random installs on work kit. Admin rights only for whoever actually needs them. Approved software list. A bookmark list of official download sites. MFA everywhere. Endpoint protection and auto-updates switched on. And one simple rule for staff: if the domain looks even slightly off, stop and ask.
Copy

Nearly 43% of UK businesses reported a cyber breach or attack in the last 12 months. That's not user error. It’s systemic digital denial. Telling people to “be more careful” when state-backed groups are building pixel-perfect deceptions is like blaming homeowners for burglary while leaving the doors off the hinges. I’m regularly invited into companies eager to spend on AI and digital acceleration, yet the moment the conversation turns to funding digital safety, enthusiasm fades. Protection still isn’t seen as productive. But there’s nothing efficient about becoming an unwitting proxy for organised crime. In an era of industrialised fraud, caution cannot be a personal hobby; it has to be a properly funded function.
Copy

If YouTube’s algorithm is sophisticated enough to detect a copyrighted song snippet within seconds of upload, it possesses the compute power to scan description links against known threat intelligence databases.

The tech giants who build their empires on top of free open source software (FOSS) like Microsoft, Google, Amazon should fund and host "Official, Verified Repositories" that guarantee the provenance of the software small businesses rely on.