Jump to content
  • Scammers are setting up fake websites to download Windows applications in latest operation

    Karlston

    • 18 views
    • 4 minutes
     Share


    • 18 views
    • 4 minutes

    Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.

    Here at Neowin, we regularly cover first- and third-party Windows applications like Wintoys, PowerToys, Windhawk, Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.

     

    This discovery was made by Wintoys developer Bogdan_X on Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:

     

    Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.

    We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.

     

    Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off. The complete list of discovered fake websites is as follows:

     

    • christitustool.com
    • droidkit.pro
    • easybcd.app
    • powertoys.app
    • shellmenuview.com
    • winexp.app
    • zhpcleaner.com
    • cursorslibrary.com
    • fakeflashtest.com
    • searchmyfiles.com
    • wintoys.app
    • themouseclicker.com
    • quickassistapp.com
    • move-mouse.com
    • movemouse.net
    • nircmd.net
    • crystaldiskinfo.app
    • freewheelofnames.com
    • productkeyscanner.com
    • power-toys.com
    • chatmate.info
    • usblogview.com
    • mouse-mover.com
    • mouse-cursors.com
    • mouse-clicker.com
    • mimalloc.com
    • mumuplayer.app
    • wushowhide.com
    • guiformat.app
    • freefilesync.net
    • winutil.app
    • spacesniffer.app
    • simplestickynotes.app
    • showmore.app
    • mousecape.app
    • hashcat.app
    • dshidmini.app
    • darktable.app
    • daijisho.app
    • wiblr.com
    • skse64.com
    • sageattention.com
    • rezygisk.com
    • pwndbg.com
    • ocrmypdf.com
    • notatnikonline.com
    • noisium.com
    • mousecape.net
    • mongosh.com
    • lspconfig.com
    • liveclockwithseconds.com
    • lax1dude.com
    • je2be.com
    • iso2god.com
    • hifiasm.com
    • hddsentinel.com
    • hakchi2.com
    • gliden64.com
    • furfsky.com
    • freeminutetimer.com
    • findoutdate.com
    • crystaldiskmark.net
    • bepisdb.com
    • beardlib.com
    • 10mintimer.com
    • pyjwt.com
    • moliyachi.com
    • arduinodroid.com
    • cxxdroid.com
    • kalkulyator.com
    • retraitedz.com
    • urlaubscountdown.com

     

    It's unclear what the goal of this supposed scamming operation is, since the domains don't seem to be doing anything obviously malicious right now. It is possible that the fake websites are posing as official sources to gain trust and traffic before eventually injecting malware in their download links.

     

    When Bogdan_X reported the fake domains to the registrar, the registrar terminated services for the scammer. However, this didn't really solve the problem as they migrated to another registrar.

     

    It's unlikely that there is a long-term solution to this problem, but users and developers should report illegal activity to the cloud hosting provider and the domain registrar if they come across it. And as always, it is better to carefully vet a URL and essentially any portal hosting a download link before you click on it.

     

    Source


    Hope you enjoyed this news post. Feedback welcome.

    Posted Tuesday 28 July 2026 at 4:45 am AEST (my time).

    News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475

    RIP Matrix


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...