I forget the name of it, but there's a fork one of the open source browsers that's distributed by neo nazi types. I stumbled onto it trying to find a copy of XP I could use in a VM to run some ancient software. I wouldn't at all be surprised if it had a backdoor.
How often do unsophisticated users identify where malware came from correctly?