Attackers have set up more than 70 lookalike websites impersonating popular Windows utility and customization apps, including Wintoys, PowerToys, WinUtil, EasyBCD, CrystalDiskMark, Lively Wallpaper, and SignalRGB, to lure users searching for downloads. The campaign was uncovered after Wintoys developer Bogdan Pătrăucean identified a cloned site for his app and traced it to a wider domain cluster linked by the anonymized WHOIS contact 43345@anonymize.com, with operators reportedly shifting domains to a new registrar after scrutiny.
Researchers said the sites use a staged approach: some initially serve legitimate installers to build trust, then later replace them with malicious downloads. Observed payloads include trojanized installers, persistent ScreenConnect remote-access software, RemusStealer, AnimateClipper, and bandwidth-sharing software, while proxy-backed hosting has helped keep parts of the infrastructure online. Some domains have been flagged by Cloudflare or added to Hagezi blocklists, but many remain active, increasing the risk for users who download Windows apps from search results instead of official developer pages or the Microsoft Store.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After an initial report on the fake-site cluster, the domain portfolio was moved to a new registrar, indicating an operational change to keep the infrastructure online.
Confirmed malicious impersonation sites were seen delivering trojanized installers and additional payloads including persistent ScreenConnect remote access software, RemusStealer, AnimateClipper, and bandwidth-sharing software.
Analysis tied the operation to a large portfolio of over 70 fake software-download domains, including sites impersonating tools such as Wintoys, PowerToys, WinUtil, EasyBCD, CrystalDiskMark, Lively Wallpaper, and SignalRGB.
Bogdan Pătrăucean, the developer of Wintoys, found a clone domain impersonating his application, which led to the broader discovery of the campaign infrastructure.
Some of the impersonation domains were flagged by Cloudflare or added to Hagezi’s DNS blocklist, although many of the sites reportedly remained active.
Check Point Research reported that the impersonation sites initially present legitimate downloads to appear benign, then later replace them with malicious payloads to infect visitors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.