Fake Windows App Websites Target PowerToys, Wintoys, and More
Fake Windows app websites are impersonating several popular utilities, including PowerToys, Wintoys, CrystalDiskMark, WinUtil, and FreeFileSync.
More than 70 related domains reportedly share the same contact email address, suggesting that one group may control the coordinated network. The websites copy the names and branding of legitimate Windows applications, but the real developers do not operate them.
Some of the websites remain under construction, which could indicate that the operation launched recently or remains in development.
Fake Wintoys website triggers phishing warning
Wintoys developer Bogdan_X discovered an unauthorized website using the wintoys.app domain.
The website includes inaccurate information about Wintoys and has no connection to the application’s developer. At the time of discovery, the website’s download button directed users to the legitimate Wintoys listing on the Microsoft Store.
However, Cloudflare displayed a warning that the domain was suspected of phishing. Bogdan_X reported the domains to their registrar. The registrar initially terminated them, but the websites later moved to another registrar and continued operating.
More than 70 domains target Windows utilities
The network reportedly includes websites impersonating a wide selection of Windows tools and open-source applications.
Targeted applications include:
- PowerToys
- CrystalDiskInfo and CrystalDiskMark
- Chris Titus Tech’s Windows utility
- NirSoft tools
- EasyBCD
- Hashcat
- Darktable
- HddSentinel
- GUIFormat
- Move Mouse
- Quick Assist
- FreeFileSync
- SpaceSniffer
The professional design and recognizable product names could make the websites appear legitimate to users searching for software downloads.
Some domains may also rank in search results or appear in AI-generated answers, increasing the chance that users will visit an unofficial page instead of the real developer’s website.
Purpose of the network remains unclear
Researchers have not confirmed that the websites currently distribute malware. Several download buttons still send visitors to legitimate stores or official download locations.
Some believe that operators want to build search traffic and establish trust before replacing legitimate links with malicious installers. Attackers often use fake software websites to distribute information stealers, remote access tools, and other malware.
How to avoid fake software download websites
Windows users should download apps only from official sources like the developer’s website, GitHub repository, or Microsoft Store.
Always check domain names carefully, as similar-looking ones may be fake. Search rankings and professional design don’t guarantee legitimacy. Verify links via official social media, GitHub, or documentation before installing.
In other security news, hackers have hijacked hotel Wi-Fi networks to steal Microsoft 365 accounts. The Chaos ransomware operation has also started using msaRAT to hide malicious traffic inside Chrome and Edge activity.
Via Neowin
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages