In a current campaign, scammers lure victims to websites that appear to offer correct download links for popular software. In the end, though, entirely different software ends up on the computer. Malware analysts at Malwarebytes have found a total of 41 websites running this scheme.
A wide range of fakes
The imitation sites range from popular games to well-known Windows tools. If you search for Counter-Strike, Half-Life, Fallout, Roblox, PUBG, The Witcher, 7-Zip, Foxit PDF, Paint.NET, Total Commander, VLC, or VMware, you could land on one of the fake pages. In the end, they're all designed to get visitors to download the installer for software called "Download Studio."
According to the analysts, the people behind the scheme put considerable effort into convincing fakes, complete with correct product information, developer resources, and even genuine download links. The trick lies elsewhere: the download links don't lead where the link target shown on mouseover indicates. On a page pretending to offer Counter-Strike for download, hovering over the download button shows a genuine Steam store address in the browser. Clicking it, however, doesn't open Steam; the page's JavaScript intercepts the click and redirects through an affiliate link, currently to Download Studio.
Undermining a classic security tip
This tactic undermines the classic advice to check a link's target before clicking, a habit that's practically second nature for many users. To improve their success rate, the operators specifically imitate popular offerings. One page for GTA 6 even claims to offer the game for PC download, complete with installation instructions and system requirements. There's no PC download to be had, though: GTA 6 officially launches on November 19 for PlayStation 5 and Xbox Series X/S, and a PC version hasn't been announced.
According to Malwarebytes, the fakes of well-known Windows tools are even more convincing. For the VLC media player, the fake page displays the correct current version and download address, but the page's click handler redirects here too, toward the affiliate download for Download Studio. The analysts stress that Download Studio itself isn't malware. In 2020, though, an update to the software once installed malware called "FakeMBAM," malicious software disguised as Malwarebytes, after attackers had compromised the vendor's update servers. If in doubt, the people behind the currently observed campaign are primarily interested in making money through affiliate downloads.
How to spot unsafe downloads
After downloading, you should check the file's digital signature. If clicking "Download VLC" leads to a file whose properties list "Download Studio" as the title, it's obviously not the software you wanted, even though attackers can of course fake such details however they like. So pay attention to the download as a whole: did it come from a trustworthy website, and does the signature come from the vendor you'd expect? The safest approach is to download software directly from the vendor's website instead of clicking links in search engine ads. The download targets of such campaigns can also change at any time and point directly to malware in the future, as happened with compromised Daemon Tools Lite installers in early May.