A text editor, a PDF converter, a game mod: these all sound harmless, and mostly are, as long as they come from the actual official source. The risk shows up when someone downloads the same-looking tool from a search result or third-party site instead, which is exactly where a lot of trojanised installers live.
These fake downloads are built to look and function identically to the real thing, at least at first, while quietly installing malware alongside, or instead of, the tool the person actually wanted.
The habit that prevents most of this is simple: download software only from the vendor's own site or a verified app store, and treat search-result links to "free" versions of paid or popular tools with real scepticism, especially on a work device.
See how goDeep turns thinking like this into training your team will actually remember.