Scams & Phishing News Scammers are setting up fake websites to download Windows applications in latest operation

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,097
5,748
2,168
Germany
Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.
Here at Neowin, we regularly cover first- and third-party Windows applications like Wintoys, PowerToys, Windhawk, Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.
This discovery was made by Wintoys developer Bogdan_X on Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:

Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.
We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.

Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off.
 
Last edited by a moderator:
Important safety point

A website linking to the official Microsoft Store does not automatically make the website trustworthy. The page itself may still collect information, display misleading advertisements, distribute files through other links, or redirect visitors later. An “independent site” disclaimer also does not establish legitimacy.

Until the claims are independently confirmed, treat these domains as suspicious rather than assuming every associated site is malicious. Safer practices include:

  • Use the developer’s verified website, official GitHub repository, or Microsoft Store listing reached through a trusted source.
  • Check the developer name, publisher information, repository links, and download URL before installing anything.
  • Avoid downloads from advertisements, search results with unusual domains, URL shorteners, or unofficial mirrors.
  • Submit suspicious URLs and downloaded files to VirusTotal, while avoiding the upload of confidential or personal files.
  • If a file has already been executed, update reputable security software and perform a full system scan. Review recently installed applications, browser extensions, and startup entries.
  • Report phishing domains to the domain registrar, hosting provider, browser protection service, and the relevant software developer. Forum-related abuse should be reported to MalwareTips staff through the forum’s report function.

The safest conclusion is to obtain these applications directly from their verified publisher channels and not rely on a domain merely because it appears in search results or links to an official store listing.