Security1 distinct publisher3 min readUpdated
Malwarebytes found a 41-site network whose download buttons hold genuine Steam and VideoLAN links, then use JavaScript to send the click elsewhere. Awareness training needs a rewrite.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Malwarebytes found a 41-site network whose download buttons hold genuine Steam and VideoLAN links, then use JavaScript to send the click elsewhere. Awareness training needs a rewrite.
Malwarebytes says it has identified a network of 41 websites impersonating popular games and Windows software, all pushing visitors toward the same installer, a program called Download Studio [1]. The consequential part is not the payload but the plumbing: the sites put real vendor URLs in their download buttons and then send the click somewhere else [3][5].
On one Counter-Strike page, hovering over the download button makes the browser display a genuine Steam Store address; clicking it does not open Steam [4]. According to Malwarebytes, JavaScript on the page handles the click separately, cancelling the expected navigation and routing the visitor through an affiliate redirect instead [5]. The page's footer links to genuine Steam resources to complete the effect [6]. The same construction appears on a fake VLC Media Player page, which places a real VideoLAN download address inside its button and names VideoLAN's servers as the source of the file [10]; the advertised version, VLC 3.0.23, was VideoLAN's current release at the time of the research [11]. Across all 41 sites the branding and advertised software change, but the destination is the same installer [1].
That is enough to retire a decade of user training. Hover-then-inspect is one of the oldest pieces of web-safety advice, and Malwarebytes itself recommends it for checking links in email [16]. Here the value the browser shows is accurate and irrelevant. The `href` is real; the navigation is scripted. Any awareness module that ends at "check where the link points" is teaching users to verify a field the attacker deliberately made truthful. The check that survives this campaign is the one taken after the click: what is in the address bar, and what is the name and publisher of the file that landed in Downloads.
The signature advice fails the same way, and more expensively. The fake VLC page recommends checking the installer's digital signature before running it [12]. Follow it and the check passes: the sample Malwarebytes examined is validly signed by Grand Media, TOV [13]. A signature establishes who signed a file and whether it has been altered since signing, not that it is the program you meant to fetch [14] - a distinction Malwarebytes notes Microsoft's own Authenticode documentation also draws [15].
The lure inventory is worth reading for what it says about targeting: Counter-Strike, Half-Life, Fallout, Roblox, PUBG and The Witcher alongside VLC, 7-Zip, Paint.NET, VMware, Total Commander and Foxit PDF [2], at least twelve named brands that a corporate endpoint plausibly requests [1]. One site, GTA 6 PLAY, advertises a PC download of Grand Theft Auto VI complete with installation instructions and system requirements [7]. Rockstar lists the game for PlayStation 5 and Xbox Series X|S with a release date of November 19, 2026, and has not announced a PC release [8][9], so the advertised file cannot be the game [2].
For filtering, the assumption to re-examine is whichever layer reasons about link targets in page content rather than the requests that actually leave the browser. A crawler or inspection proxy that scores the href reads these pages as pointing at store.steampowered.com and videolan.org. Blocking value sits at the affiliate redirect chain and the installer, not at 41 replaceable domains.
Watch for revocation of the Grand Media, TOV signing certificate [13], for the network expanding past 41 hosts [1], and for a lure surge around the November 19, 2026 console release [9].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The sites advertise Counter-Strike, Half-Life, Fallout, Roblox, PUBG and The Witcher, as well as VLC, 7-Zip, Paint.NET, VMware, Total Commander and Foxit PDF.
The VLC lure recommends checking the installer's digital signature before running it, including via right-click, Properties, Digital Signatures tab.
The Download Studio installer passes the digital signature check; the sample Malwarebytes examined is validly signed by Grand Media, TOV.
Malwarebytes identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors toward the same Download Studio installer; across the 41 sites the branding and advertised downloads change but the destination software is the same.
The sites use accurate product information, genuine developer resources and real download links to look convincing.
On one site promising Counter-Strike, hovering over the download button makes the browser display a genuine Steam Store address, but clicking the button does not open Steam.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific first-party research, no independent corroboration or indicators
The single source is the researching vendor and it supplies concrete, checkable mechanism detail: the href-versus-click-handler divergence, a genuine VideoLAN address and the then-current VLC 3.0.23 version string, a named signer (Grand Media, TOV) whose signature validates, an approximate installer size, and post-install behavior. Against that, nothing in the cluster is independently verified, no domains, hashes or certificate identifiers are published in the supplied text, and the 41-site count and the single shared destination rest entirely on the vendor's assertion.
Campaign footprint documented, victim-side impact not
Deployment on the attacker side is documented and non-trivial: 41 live sites, a dozen-plus impersonated brands spanning games, everyday utilities and even security, backup and recovery products, and one shared installer with an affiliate-tracked redirect. What is absent is any measure of reach or uptake — no visit or download counts, no install telemetry, no geography, no detections or user reports, and no indication that platforms, registrars or certificate authorities have acted. So the technique is shown to be in production but its scale of effect is unmeasured.
Framing outruns the vendor's own harm finding
The mechanism is real and the guidance failure is genuinely demonstrated, so the story is not inflated at its core. The overstatement is modest and sits in the framing: 'hover-to-check is broken' generalizes a click-handler override on attacker-controlled pages into a wholesale failure of link inspection, while the vendor itself states its analysis did not establish that Download Studio is malware and reports no victim impact. A reader could come away expecting confirmed malware distribution where the documented outcome is deceptive funneling into unwanted software with affiliate monetization.
Vendor-authored threat intel; attacker side is affiliate-monetized
Two incentive layers are visible in the supplied material. The only publisher is a consumer security vendor writing up its own research, which structurally rewards findings that show ordinary user precautions failing; the post nonetheless self-limits by declining to call the payload malware, which cuts against pure promotional framing. On the attacker side the report states the redirect includes affiliate tracking, suggesting a commercial incentive, and the installer pushes to become the default torrent client with an auto-updater enabled — monetization and persistence motives rather than obvious espionage or destruction.
Credible primary research, unverified and unreplicated
Confidence is capped by structure rather than by content quality: one publisher, that publisher being the researcher, no second-party replication, and no published indicators that would let a reader check the 41-site count or the signer attribution. Within those limits the specifics are internally consistent and the report states its own boundaries, and the externally checkable element in the cluster — that Rockstar lists Grand Theft Auto VI for PS5 and Xbox Series X|S on November 19, 2026 with no PC release announced — is the kind of claim that makes the GTA lure conclusion sound.
product
Cyberleek dumped GTA 6 footage nine days early, with a memecoin attached and no provenance2 distinct publishers
security
A staging password went into a Google Doc, and Google's autocomplete found it first1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
product
The criminal AI market is a reseller business, and Grok's abuse desk is the chokepoint1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026