Be careful downloading Windows 11 apps from Google, 70+ fake sites are pushing malware right now
RSS
Youtube
Windows 11
Windows 10
Windows 10 PC Apps & Games
Privacy Policy
Contact Us
About us
Select Theme:
System
Light
Dim
Dark
Search
Sign in
Welcome! Log into your account
your username
your password
Forgot your password? Get help
Create an account
Create an account
Welcome! Register for an account
your email
your username
A password will be e-mailed to you.
Password recovery
Recover your password
your email
A password will be e-mailed to you.
Windows Latest
Windows 11
Be careful downloading Windows 11 apps from Google, 70+ fake sites…
I spent 25+ years at Microsoft, and Windows is getting the…
Microsoft admits Windows 11 native apps hog RAM, promises a WinUI…
Microsoft actually doesn’t care about your pirated Windows 11, despite the…
Windows 11’s File Explorer is now faster at deleting large files,…
Windows 10
AllWindows 10 PC Apps & Games
HP admits 30% of PCs still run Windows 10, rejecting Windows…
Windows 10 KB5099539 out with RDP security upgrade, direct download links…
Microsoft’s new Windows 10 ESU email doesn’t push Windows 11, just…
Windows 10 is still getting Windows 11 features, but it’s only…
Privacy Policy
Contact Us
About us
Select Theme:
System
Light
Dim
Dark
Trending:Remove Recall AI
New Start menu
Windows 11 25H2
New Windows 11 ISO
Windows 11 24H2
Windows 11 AI requirements
Restore WordPad
Home Windows 11
Windows 11
More than 70 popular Windows apps now have fake websites impersonating them, and some are already serving malware. The list includes widely used tools like PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, all cloned onto lookalike domains that in most cases rank above the real project pages on Google.
Some apps on this list have already had their fake sites confirmed as active malware distributors. They may be pushing a trojanized installer that sets up a remote-access service on victims’ PCs.
Credit: u/Bogdan_X via Reddit<br>We strongly recommend downloading Windows apps only from the Microsoft Store or from the developer’s official website or GitHub page, and never from a random search result, however convincing it looks. If you’ve visited any of the following websites, treat your PC as compromised and scan it immediately:
Full list of fake websites impersonating Windows apps
The following domains were identified as impersonating legitimate Windows applications, all registered to the same owner through Epik Inc. before being moved to Dynadot LLC in July. Remember, not a single one of these is an official source for the apps it claims to represent, and please do not open these URLs. For testing, you can use Windows Sandbox.
Again, in case we are not clear already, steer clear of every domain on this list. They are not affiliated with the developers whose apps it claims to host.
How a developer discovered 70+ lookalike domains while checking his own app’s reviews
The developer behind Wintoys, a Windows optimization tool available on the Microsoft Store that lets users clean, repair, and tweak system settings without opening the terminal, habitually searches his app’s name on Google to see new reviews or user questions. During one of these searches, he found a domain he had not purchased showing up in the results (wintoys.app).
u/Bogdan_X, who reached out to Windows Latest with their findings, explained that the site was built on WordPress, with generic, inaccurate AI content, and used their old logo. Its download button surprisingly goes to the real Microsoft Store listing, which is likely why it hadn’t raised alarms yet.
He tried to trace ownership of the domain but couldn’t, since it was registered through Epik Inc., which bundles free WHOIS privacy into every domain, keeping the buyer’s identity hidden by default. What he did find was a troubling list of 72 domains.
Even Microsoft’s own PowerToys has a fake website!
These sites build trust first, then swap in malware later
According to Check Point Research, these impersonation sites have a three-stage playbook:
They rank for a popular app’s name in search results
Appear harmless at first by linking to real download sources
Then quietly swap those links for malware after getting traffic and trust.
Impersonated websites of popular software tools (Source: Check Point Research)<br>Check Point found that some of these sites load a script from Amazon CloudFront that intercepts the click on a download button and reroutes it through a Traffic Distribution System, a filtering layer that decides where to send each visitor based on their location, browser, and whether they look like a bot or a security researcher.
Check Point traced malware families including RemusStealer, an infostealer targeting over 20 browsers and cryptocurrency wallets, and AnimateClipper, which swaps copied crypto wallet addresses for the...