As someone who manages servers, I can tell you that's not true. Cybercriminals will hijack anything to do their bidding. Massive botnets of infected PCs are the stuff of nightmares for any sysadmin. New waves of attacks spawn as quickly as you can put down the previous wave.
That's not enough. You can very easily get snookered into downloading the wrong software through a deceptively designed banner ad that's showing on a legitimate software download site. You can also get tricked into visiting a shady site through browser hijacking banner ads, which have been known to run on MacRumors from time to time before they're caught.
You can click a link to a site that vanished, but had their domain re-registered by a criminal ring in some Eastern Bloc country to redirect you somewhere to trick you into downloading fake Adobe Flash updates or a tainted Java package.
The "just don't do anything stupid defense" that is commonly passed around MR is a good start, but it isn't much of a defense.