Skip to main content
LiMP VPN
All news

70+ Fake Windows App Sites Are Spreading Malware

70+ Fake Windows App Sites Are Spreading Malware

In short: In late July 2026, Check Point researchers exposed a network of more than 70 lookalike sites impersonating popular Windows apps — including PowerToys, CrystalDiskMark, WinUtil, Lively Wallpaper, Wintoys and SignalRGB. The fake pages often outrank the originals on Google, link to the real download at first, then swap the download button for malware that steals passwords, cookies and crypto wallets. The main defence is simple: download software only from official sources.

What happened?

In late July 2026 Check Point published an analysis of a large-scale campaign that spreads malware through fake Windows-utility websites. The scheme was first noticed by the developer of the Wintoys app, after which researchers mapped the whole infrastructure: over 70 lookalike domains posing as the official pages of free programs. According to their findings, the campaign has been running since at least January 2026.

What makes this dangerous is how ordinary it is. There is no server hack and no exotic vulnerability — just the most routine action there is: you search for the name of a tool you need, click the first link and download the installer. This is exactly how a single password leak can set off a chain of break-ins, as we showed in our report on the massive password leak from info-stealers. The trouble is that the fake sites often look more convincing than the real one and sit above it in search results.

How does the scheme work?

The attack follows a patient, three-step playbook. First, the operators stand up a clone site using the name and look of a well-known program and push it up the search results for a query like "PowerToys download." Second, for a while the site behaves honestly — the download button points to the real source, which lulls both users and security scanners. Only in the third step, once it has gathered traffic and trust, do the operators swap the link: the "Download" button starts serving a malicious installer.

To dodge analysis, the network runs a traffic distribution system (TDS) built on an Amazon CloudFront script. It decides what to show each visitor based on location, browser and whether they look like a bot or a researcher: an ordinary user gets the infected file, while anyone resembling a security analyst is served a harmless page. That is what makes these fakes so hard to catch and take down.

What malware does it deliver?

Check Point linked the infrastructure to several malware families. The main one is RemusStealer, a newly emerged info-stealer that pulls data from more than 20 browsers and targets hundreds of extensions and applications, including cryptocurrency wallets, password managers and two-factor authentication apps. Alongside it are AnimateClipper, a "clipper" that swaps copied wallet addresses in the clipboard across 20+ blockchain ecosystems, and SessionGate, a multi-stage loader with heavy anti-analysis defences. Some installers also carry persistent backdoors for remote access to the machine.

What does this mean for you and your data?

A single installer you run can cost you every password and session cookie saved in your browser — and with them, access to your email, social accounts and work services without ever typing a password. Cryptocurrency is a separate target: the clipper quietly changes the recipient address so your transfer goes to the attackers. Stolen credentials then fuel new attacks — used to break into other accounts and to send targeted phishing. A no-logs VPN is one layer of the defence, and we explain how the layers fit together on our features page.

How to stay safe when downloading software

Download only from the official source. Reach the developer's site through a bookmark or a verified address, and for open-source projects take releases from the project's own GitHub page. Do not trust the ranking in search — the top spot can be an ad or a lookalike site.

Check the address and publisher. Read the domain letter by letter (clones rely on typos and extra words), and after installing, verify the file's digital signature. An unknown or missing publisher is a reason to stop.

Keep antivirus and updates on. An up-to-date defender and a patched system catch a large share of these installers. Do not disable checks to "speed up" a download.

Layer your defences. It is worth being honest here: a VPN will not replace antivirus and will not stop malware you downloaded and ran yourself. But a no-logs VPN protects a different layer of privacy — it encrypts your traffic on untrusted networks and hides your real IP so networks and trackers cannot profile your activity. That is how digital safety is built: in layers, as we show on the features page of LiMP VPN. More practical guides live on our blog.

Sources

This report is based on research by Check Point Research and coverage by TechSpot (July 2026).

70+ Fake Windows App Sites Are Spreading Malware | LiMP VPN