Recently, a significant security risk has emerged in the cybersecurity landscape: Over 70 well-known Windows applications are facing threats from large-scale fake websites. Hackers have created counterfeit versions of the official websites for popular tools such as PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, using highly similar domain names and page designs to deceive users. These fake sites not only steal old logos, provide installation tutorials, and system requirement descriptions but also include authentic links to the Microsoft Store to camouflage (disguise themselves) as trustworthy channels. The attackers employ a 'nurturing' strategy, initially using clean shells to gather traffic and then replacing the download links with malicious payloads embedded with remote control Trojans once the traffic volume is sufficient. Security research firm Check Point analyzed that such attacks occur in three steps: First, they hijack search traffic using brand names; second, they provide harmless downloads of the genuine software; and finally, they replace them with malicious versions once the traffic meets their threshold. Currently, the fake page for the dynamic wallpaper software Lively Wallpaper has been distributing installation packages embedded with the ScreenConnect remote access tool and bandwidth-sharing software, turning victims' computers into 'bots.' The maintainer of the RGB lighting control suite SignalRGB has also issued a warning, stating that its domain is distributing malware. These cases demonstrate that once fake sites establish an impression of being 'trustworthy channels,' remote access tools can be weaponized and seamlessly integrated into the attack process. More concerningly, after developer Bogdan_X reported the discovered domain cluster to the first registrar, the operator quickly transferred the entire domain asset portfolio to a new registrar, allowing all fake sites to survive. Since the hosting services are hidden behind a large proxy network, the content is difficult to remove promptly. Some incomplete cloned pages remain online to this day, suggesting that more software may be targeted in the future.
