Fake Windows App Sites Spread Malware, 70+ Domains Found

Share:

Loading

Typing a Windows app name into Google and trusting the top result has always been a bit of a gamble. Now that gamble comes with much higher stakes. Researchers found a network of more than 70 fake websites copying popular Windows tools, including Microsoft PowerToys, CrystalDiskMark, EasyBCD, Wintoys, Lively Wallpaper, and SignalRGB.

According to Windows Latest, a lot of these copycat sites rank higher than the real site pages on Google, even though they have zero connection to the actual developers.

fake Windows app website

Right now, some of these fake sites point their download buttons to legitimate Microsoft Store listings. That’s likely a tactic to build trust before the real attack kicks in.

Fake Windows App Sites Spread Malware

This whole thing came to light because of the Wintoys developer. He stumbled on “wintoys.app”, a copycat site using an outdated version of his logo and content that read like it was written by AI, generic and off.

fake Windows app websites

When he dug into the domain registration, he found 72 other sites registered through the same company. All part of the same setup.

You may also like: Windows 11 Media Player Update: Slower and Memory Heavy

Check Point’s security team looked deeper and found something sneakier going on. These fake sites don’t start out malicious. At first, they link to the real software. That’s how they pull in visitors and climb up Google’s rankings.

But once a site earns enough trust and traffic, JavaScript on the page can hijack a click and route the visitor through what’s called a Traffic Distribution System. This system decides where you actually land based on your location, your browser, whether you’re using a VPN, and even whether you look like a security researcher poking around.

Depending on who you are, you might get sent to real software, or something harmless but unwanted. Or you might get hit with actual malware.

One strain researchers found, RemusStealer, goes after browser data, saved passwords, crypto wallets, and login credentials. Check Point tracked over 100 active sites running these routing scripts, and more than 5,000 related file submissions on VirusTotal tied to the same campaign.

Some Cloned Apps Working as Malware

One fake Lively Wallpaper site handed out an installer packed with a bad DLL file, software that gives attackers continuous remote access to your machine, and a program that quietly shares your bandwidth without asking.

The real Lively Wallpaper developer came out and confirmed he has nothing to do with that site. SignalRGB ran into the same problem, flagging two fake domains that show up near the top of search results. If you grabbed an installer from either one, delete it now and run a full malware scan right away.

You may also like: Microsoft Edge Collections Shutdown: What You Need to Know

The safest move you can do is simple. Download only from the Microsoft Store, the developer’s official site, or their GitHub page. Before you click download anywhere else, check the actual domain name carefully.

Make sure the installer has a valid digital signature. And don’t assume that just because a link sits at the top of your Google results, it’s the real one. Google’s ranking doesn’t mean official.