Security1 publisher3 min readPublished
Hover-to-check is broken: 41 fake download sites show a real URL, then route the click
Malwarebytes found a 41-site network whose download buttons hold genuine Steam and VideoLAN links, then use JavaScript to send the click elsewhere. Awareness training needs a rewrite.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Malwarebytes identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors toward the same Download Studio installer; across the 41 sites the branding and advertised downloads change but the destination software is the same.
- The sites advertise Counter-Strike, Half-Life, Fallout, Roblox, PUBG and The Witcher, as well as VLC, 7-Zip, Paint.NET, VMware, Total Commander and Foxit PDF.
- The sites use accurate product information, genuine developer resources and real download links to look convincing.
- On one site promising Counter-Strike, hovering over the download button makes the browser display a genuine Steam Store address, but clicking the button does not open Steam.
- JavaScript on the page handles the click separately: instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Malwarebytes says it has identified a network of 41 websites impersonating popular games and Windows software, all pushing visitors toward the same installer, a program called Download Studio [1]. The consequential part is not the payload but the plumbing: the sites put real vendor URLs in their download buttons and then send the click somewhere else [3][5].
On one Counter-Strike page, hovering over the download button makes the browser display a genuine Steam Store address; clicking it does not open Steam [4]. According to Malwarebytes, JavaScript on the page handles the click separately, cancelling the expected navigation and routing the visitor through an affiliate redirect instead [5]. The page's footer links to genuine Steam resources to complete the effect [6]. The same construction appears on a fake VLC Media Player page, which places a real VideoLAN download address inside its button and names VideoLAN's servers as the source of the file [10]; the advertised version, VLC 3.0.23, was VideoLAN's current release at the time of the research [11]. Across all 41 sites the branding and advertised software change, but the destination is the same installer [1].
That is enough to retire a decade of user training. Hover-then-inspect is one of the oldest pieces of web-safety advice, and Malwarebytes itself recommends it for checking links in email [16]. Here the value the browser shows is accurate and irrelevant. The `href` is real; the navigation is scripted. Any awareness module that ends at "check where the link points" is teaching users to verify a field the attacker deliberately made truthful. The check that survives this campaign is the one taken after the click: what is in the address bar, and what is the name and publisher of the file that landed in Downloads.
The signature advice fails the same way, and more expensively. The fake VLC page recommends checking the installer's digital signature before running it [12]. Follow it and the check passes: the sample Malwarebytes examined is validly signed by Grand Media, TOV [13]. A signature establishes who signed a file and whether it has been altered since signing, not that it is the program you meant to fetch [14] - a distinction Malwarebytes notes Microsoft's own Authenticode documentation also draws [15].
The lure inventory is worth reading for what it says about targeting: Counter-Strike, Half-Life, Fallout, Roblox, PUBG and The Witcher alongside VLC, 7-Zip, Paint.NET, VMware, Total Commander and Foxit PDF [2], at least twelve named brands that a corporate endpoint plausibly requests [1]. One site, GTA 6 PLAY, advertises a PC download of Grand Theft Auto VI complete with installation instructions and system requirements [7]. Rockstar lists the game for PlayStation 5 and Xbox Series X|S with a release date of November 19, 2026, and has not announced a PC release [8][9], so the advertised file cannot be the game [2].
For filtering, the assumption to re-examine is whichever layer reasons about link targets in page content rather than the requests that actually leave the browser. A crawler or inspection proxy that scores the href reads these pages as pointing at store.steampowered.com and videolan.org. Blocking value sits at the affiliate redirect chain and the installer, not at 41 replaceable domains.
Watch for revocation of the Grand Media, TOV signing certificate [13], for the network expanding past 41 hosts [1], and for a lure surge around the November 19, 2026 console release [9].