Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.
Here at Neowin, we regularly cover first- and third-party Windows applications like
Wintoys,
PowerToys,
Windhawk,
Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.
This discovery was made by Wintoys developer Bogdan_X on
Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:
Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.
We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.
Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off. The complete list of discovered fake websites is as follows:
christitustool.com
droidkit.pro
easybcd.app
powertoys.app
shellmenuview.com
winexp.app
zhpcleaner.com
cursorslibrary.com
fakeflashtest.com
searchmyfiles.com
wintoys.app
themouseclicker.com
quickassistapp.com
move-mouse.com
movemouse.net
nircmd.net
crystaldiskinfo.app
freewheelofnames.com
productkeyscanner.com
power-toys.com
chatmate.info
usblogview.com
mouse-mover.com
mouse-cursors.com
mouse-clicker.com
mimalloc.com
mumuplayer.app
wushowhide.com
guiformat.app
freefilesync.net
winutil.app
spacesniffer.app
simplestickynotes.app
showmore.app
mousecape.app
hashcat.app
dshidmini.app
darktable.app
daijisho.app
wiblr.com
skse64.com
sageattention.com
rezygisk.com
pwndbg.com
ocrmypdf.com
notatnikonline.com
noisium.com
mousecape.net
mongosh.com
lspconfig.com
liveclockwithseconds.com
lax1dude.com
je2be.com
iso2god.com
hifiasm.com
hddsentinel.com
hakchi2.com
gliden64.com
furfsky.com
freeminutetimer.com
findoutdate.com
crystaldiskmark.net
bepisdb.com
beardlib.com
10mintimer.com
pyjwt.com
moliyachi.com
arduinodroid.com
cxxdroid.com
kalkulyator.com
retraitedz.com
urlaubscountdown.com
It's unclear what the goal of this supposed scamming operation is, since the domains don't seem to be doing anything obviously malicious right now. It is possible that the fake websites are posing as official sources to gain trust and traffic before eventually injecting malware in their download links.
When Bogdan_X reported the fake domains to the registrar, the registrar terminated services for the scammer. However, this didn't really solve the problem as they migrated to another registrar.
It's unlikely that there is a long-term solution to this problem, but users and developers should report illegal activity to the cloud hosting provider and the domain registrar if they come across it. And as always, it is better to carefully vet a URL and essentially any portal hosting a download link before you click on it.
source