
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Researchers and a Windows app developer uncovered a campaign using lookalike “official” software download websites that rank highly in Google results. The sites initially serve legitimate downloads to build trust, then quietly swap the download links to malware that can steal credentials and cryptocurrency or install unwanted software.
This campaign relies on dozens of lookalike websites built to impersonate popular Windows app download pages, with researchers identifying 72 or more domains involved. Rather than launching with malicious downloads right away, the sites initially serve legitimate installers. This early legitimacy helps the pages climb search rankings and build user trust. Once a site gains traction, operators quietly swap the real download links for fraudulent ones that deliver malware capable of stealing credentials and cryptocurrency, or installing unwanted software.
Some of these sites go further with a technical layer: JavaScript loaded via Amazon CloudFront intercepts clicks on Download buttons and reroutes the connection through a Traffic Distribution System. That system then sends users to either malware-hosting infrastructure or legitimate resources, depending on their location, browser type, and other signals, making the malicious behavior inconsistent and harder to spot.
The operation succeeded by exploiting search engine trust rather than email or messaging. Because the fake sites rank highly on Google for searches tied to popular Windows software, users searching for a familiar tool encounter a convincing clone sitting right alongside, or even above, the genuine project. Several of the domains use URLs deliberately close to the real ones they impersonate, making a casual glance insufficient to catch the deception. The delayed swap from legitimate to malicious links also means that even cautious users who verified the site earlier could later download a compromised installer without any change in their own behavior.
Organizations and individuals should verify they are on the actual vendor domain or official repository before downloading software, rather than trusting search ranking alone. Since sites may serve real downloads before switching to malware, past safe experience with a site is not a guarantee of continued safety. Any redirect or inconsistent behavior after clicking a download link should be treated as suspicious and reported. Finally, because payloads in this campaign include credential-stealing and crypto-wallet-draining malware, such as tools that swap clipboard-copied wallet addresses for attacker-controlled ones, users should avoid installing software from unverified sources even when it resembles a well-known utility.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They clone popular Windows app download pages using lookalike domains, initially link to legitimate downloads to build trust and search ranking, then quietly swap those links for fraudulent malware installers once traffic grows.
Some sites load a JavaScript staging layer via Amazon CloudFront that intercepts clicks on Download buttons and reroutes the connection through a Traffic Distribution System, which then sends users to either malware or legitimate resources depending on signals like location and browser type.
Payloads linked to this ecosystem include SessionGate, a multi-stage loader, RemusStealer, an info-stealer, and AnimateClipper, which reads a device's clipboard to swap copied crypto wallet addresses for attacker-controlled ones.
Verify you are on the real vendor domain or official repository before downloading, and stay cautious even if a download seemed safe before, since operators can swap legitimate links for malicious ones later.
You Google a Windows tool, click the top “official” download site, install it… and that’s how SessionGate and RemusStealer walk in. There’s a whole network of cloned download sites, like grpcurl[.]com, that first serve legit installers, then quietly swap those links to malware that can steal logins or drain crypto. On some fakes, a hidden JavaScript layer from Amazon CloudFront hijacks your click on “Download,” quietly routing you through a Traffic Distribution System that decides whether you get malware or something harmless. Here’s the move: before you download, glance at the address bar and only install from the real vendor domain or official repo, think github.com or the vendor’s exact site, not a lookalike in the top Google result.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…