S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T24.25
CATEGORY Internet Scams
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Malware Delivery

Technical Fraud · Self-Install Lure · Very Common
Red Flag
How It WorksSEC 01

Malware delivery is a persuasion problem, not a technical one. The most reliable way onto a modern, patched device is not an exploit but the user’s own click: convince a person to open, run, allow, or install something, and their permissions become the attacker’s. The malicious file is disguised as something you want or expect, and the surrounding message supplies a reason to act now and to override the warnings that would otherwise stop you. This entry describes only what a victim sees and how to avoid being tricked — no detail of how malware is written, packaged, or made to work.

Victims meet a recognizable set of disguises. Unexpected attachments arrive as invoices, receipts, résumés, or shipping notices — sometimes a document that then asks you to “enable content” or “enable macros” to “see” it (a real document never needs that). Fake updates and installers pose as a browser, media player, or security tool, often via a pop-up or a poisoned download ad rather than the vendor’s own app. “Copy-paste” / fake-verification lures instruct you to paste text into a system dialog or press a key sequence “to prove you’re human” or “fix” a page.

In every case the payload is downstream and irrelevant to defense; what matters is the victim-visible pattern — an unexpected file or prompt, a story that pressures you to run it, and a request to bypass a warning. Its defining feature for you: you are being asked to be the one who installs it.

Warning SignsSEC 02
  • An unexpected file or download. Especially an executable, installer, script, or archive — or a document demanding you "enable content/macros" to view it.
  • A browser-borne update prompt. A "software update" or "your device is at risk" pop-up while browsing — real updates come from the app/OS or the vendor's site, not a web pop-up or ad.
  • "Paste this to verify." Instructions to paste text into a system box or press a key sequence "to verify" or "to fix" — no legitimate site asks that.
  • A download from an ad or third-party site. Rather than the official source you typed in.
  • A disguised file type. Double extensions, "invoice.pdf.exe"-style names, or an archive hiding the real type.
  • A warning you're urged to ignore, or an unmentioned file "from" a known contact.
Frequently Paired WithSEC 03
  • Phishing · T14.2
    The message channel that delivers the lure
  • Tech-Support Scams · T24.3
    Remote-access sessions install it
  • Account Takeover · T24.10
    Infostealer output feeds it
  • Baiting · T14.4
    Enticing media or a found USB drives the run
How the Scam UnfoldsSEC 04
  • Stage 01 · Disguise
    An unexpected file, installer, or on-screen prompt arrives dressed as something you want or expect.
  • Stage 02 · Pressure
    A reason to act now — an overdue invoice, a "required update," a "prove you're human" step — pushes you past the warning.
  • Stage 03 · The Click
    You run, allow, or "enable" it — and your permissions become the attacker's.
Counter-ProtocolSEC 05
Defense: You are the last control — if you only install from official sources and never enable or paste on request, the disguise doesn't matter.
  • Don't run, open, or install what you didn't seek out. Get software and updates only from the vendor's own site or the official app/OS store; let apps self-update.
  • Never "enable content/macros" on an unexpected document — a legitimate file never needs it.
  • Never paste commands or press key sequences a web page tells you to "verify" or "fix."
  • Verify unexpected files out-of-band. Confirm anything "from a contact" through a second channel; keep systems patched, endpoint protection on, daily use non-admin, and offline backups current.
  • If you already ran something: disconnect, scan, change passwords from a clean device, and report to IC3, the FTC, and CISA — and don't pay a ransom first.