41 deceptive download sites show a real link, then send you somewhere else
Brief
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer.
The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF.
- •
- •
- •
- •
- •
- •
- •
- •
- They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links.
But the link you see isn’t the link you follow.
One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens.
The link looks safe when you hover, but the click says otherwise.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
41 deceptive download sites show a real link, then send you somewhere else
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer.
The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF.
- •
- •
- •
- •
- •
- •
- •
- •
- They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links.
But the link you see isn’t the link you follow.
One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens.
The link looks safe when you hover, but the click says otherwise.
One of the oldest web-safety tips is to hover over a link before clicking it and inspect the destination shown by your browser. We even recommend doing this when checking emails for phishing links and scams.
But it isn’t foolproof. This campaign shows how a site can display a legitimate destination when you hover over a link, then send you somewhere completely different when you click it.
On the Counter-Strike page, the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it.
But JavaScript on the page handles the click separately. Instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect.
The legitimate Steam URL provides reassurance, but isn’t the actual destination.
The page goes further by linking to genuine Steam resources in its footer and presenting itself as a straightforward source of technical information. That veneer disappears the moment the download button is pressed.
41 sites, one destination
The Counter-Strike site isn’t an isolated example.
41 deceptive download sites show a real link, then send you somewhere else
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer.
The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF.
- •
- •
- •
- •
- •
- •
- •
- •
- They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links.
But the link you see isn’t the link you follow.
One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens.
The link looks safe when you hover, but the click says otherwise.
One of the oldest web-safety tips is to hover over a link before clicking it and inspect the destination shown by your browser. We even recommend doing this when checking emails for phishing links and scams.
But it isn’t foolproof. This campaign shows how a site can display a legitimate destination when you hover over a link, then send you somewhere completely different when you click it.
On the Counter-Strike page, the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it.
But JavaScript on the page handles the click separately. Instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect.
The legitimate Steam URL provides reassurance, but isn’t the actual destination.
