Skip to content

Security1 publisher2 min readPublished

More than 100 look-alike subscription sites use genuine Google sign-in, with prices from under $10/month to over $2,000/year

Malwarebytes found no malware and no fake login form across the network, so the sites pass every check a user is trained to run, and the companies selling the annual plans stay anonymous.

The Watch · Security desk

Photograph accompanying More than 100 look-alike subscription sites use genuine Google sign-in, with prices from under $10/month to over $2,000/year
Photo: malwarebytes.com

What happened

  • Malwarebytes found more than 100 subscription sites it links through one toolkit and closely related developer details, and says a single operator or closely connected group is behind them.
  • Some sites imitate existing products including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, and one trades on the name of Omegle, the chat service that shut down in 2023.
  • Malwarebytes found polished product pages and genuine Google sign-in screens leading to paid plans, and the sites it examined came back clean: no fake password forms, no malware downloads.
  • Plans run from less than $10 a month to more than $2,000 a year, and on the sites examined signing in produced a pricing page instead of the tool, so payment came before any test of the product.
  • The sites run on the same commercial website starter kit, a legitimate product whose vendor advertises that a customer can launch a product in an hour.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The two checks awareness training leans on, the padlock and the domain of the login page, both come back clean here, so the only remaining test is whether the buyer can establish who is taking the money.
  • cost A chargeback is the buyer's one route to a refund, because billing runs through the kit's built-in component and the company named on the page is unverifiable.
  • exposure Buyers hand over more than the subscription fee: several sites ask for documents, recordings and other files, and those go to an operator Malwarebytes was unable to name.
  • precedent Take down the domains one at a time and the operator's cost stays where it is, since the kit is already paid for and the next brand needs only a fresh domain, design and product description.

The kit behind all of them is a legitimate commercial product. It includes an account system, billing, file storage and administrative tools, and the buyer supplies the branding and the product being advertised [15]. That is why sites selling voice-cloning tools, video editors, study apps and general-purpose assistants have identical checkout pages and identical account settings [14][16].

Some of them never had the demonstration content cleared out. Several still show the kit's own brand name, its promotional banners, generic menu entries and testimonials from named people and companies with no apparent connection to the service on sale [18]. One had relabelled the kit's sample list of businesses as its own customers. On another, the word "boilerplate" was still in the name of a paid subscription plan [19].

Site owners supply their own figures. One site claimed more than 12 million users [7]. Another displayed the names of well-known companies as customers, and Malwarebytes found no evidence that those businesses were connected to it [8]. Ratings, customer counts, testimonials, test results: the site owner types them onto the page [9].

The kit costs $249 as a one-time purchase, and extra templates run about $2 each [17]. A hundred templates at that price is $200, so the software behind the whole network costs roughly $449 [1]. One annual subscription at the top of the advertised range pays for that more than four times over [2]. Malwarebytes gave the kit's price and its vendor's marketing claim but kept both names out of it [3].

The checks a user is taught to run all pass. The padlock certifies that traffic between the browser and the site is encrypted, and ownership is a separate question it never answers [6]. Because the password goes into Google's own page at a Google address, a user watching for a spoofed login domain is looking at the genuine one [20]. The links between the brands are visible only to someone comparing the sites: identical underlying files and closely related developer email addresses [5].

Many legitimate services charge before use, and Malwarebytes locates the problem in the seller: who takes the payment stays unknown, and the page's claims have nothing independent to check them against [13].

What to watch

  • Whether Google acts against the sign-in integrations, the one step that would affect all 100-plus domains at once.
  • Whether the starter kit and its vendor are identified, and whether the vendor's terms bar this use.
  • Whether any buyer reports paying for a product that never appeared, which is what a fraud case would need.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories