Consider carefully before downloading your next app for Windows 11 from Google.
Your Windows app search results have become a malware threat
Searching for a Windows utility on Google and clicking the first appealing link has always come with some risks. Recently, a newly discovered network of fraudulent websites has made this practice considerably more perilous. Over 70 domains were found mimicking well-known Windows applications, including Microsoft PowerToys, CrystalDiskMark, EasyBCD, Wintoys, Lively Wallpaper, and SignalRGB.
According to Windows Latest, many of these imitation sites appear higher than the authentic project pages in Google results, despite having no affiliation with the actual developers. Some currently direct their download buttons to genuine Microsoft Store pages, which could be part of the attack strategy.
The deceptive sites may gain your trust before turning malicious.
The Virus and threat protection screen in the Windows Security app on Windows 11. Digital Trends
This operation emerged when the developer of Wintoys discovered "wintoys.app", an unofficial site featuring an outdated version of the app's logo and generic content generated by AI. Following the domain led to the discovery of 72 similar addresses that were initially registered through the same entity.
Security researchers at Check Point documented a broader network employing a particularly cunning approach. The impersonation websites can initially link to authentic software to draw in visitors and improve their search rankings. JavaScript can then intercept a click and reroute specific users through a Traffic Distribution System that alters the destination based on factors like location, browser, VPN usage, and whether the visitor resembles a security researcher.
Some visitors may receive either legitimate or unwanted software, while others have encountered malware, including RemusStealer, which targets browser data, password managers, cryptocurrency wallets, and authentication tools. Check Point identified over 100 active sites utilizing related routing scripts and more than 5,000 VirusTotal submissions associated with this operation.
Certain cloned apps are already distributing malware.
Sunrise King / Unsplash
A counterfeit Lively Wallpaper site shared a trojanized installer that included a harmful DLL, a persistent remote access service, and bandwidth-sharing software. The legitimate developer confirmed that the domain had no affiliation with the project. SignalRGB has also alerted users about two mimic domains prominently featured in search results. Those who downloaded an installer from either site have been advised to remove it and conduct a comprehensive malware scan.
To minimize risk, it's best to rely solely on the Microsoft Store or the verified website of the developer or their GitHub page. Always verify the domain prior to downloading, ensure that installers have a valid digital signature, and refrain from assuming that the top result on Google is the official one.
Other articles
Consider carefully before downloading your next app for Windows 11 from Google.
Over 70 websites are impersonating well-known Windows utilities, featuring convincing replicas that rank in search results, and some are already distributing trojanized installers to unaware users.
