"One of the biggest threats I see is if bad actors leverage the band's popularity for their personal gain," he says, "a threat actor might share a malicious fandom application, luring fans in. Then, after a few weeks, their devices could be used collectively to launch an attack against a third party; essentially, launching a DDoS attack."
Picture this: you find on twitter (or anywhere else) a link to a website promising it's the ultimate fandom website in the web, maybe ARMY. The website only needs to infect your computer with malware to unsuspectingly recruit you. You visit the website for long enough to learn that the website is not as great as promised and leave to never return; but you stay long enough for the website to infect your computer. Then when a specific date and time is reached, the malware in your computer, along with the infected computers of thousands of other fans, launches an attack on the targeted website. You only need to visit a malicious website for a few minutes in order to be recruited, nothing else. In this scenario, it's possible for such a threat to exist. Not that the fans are the actual threat; but that they could be used to those ends.