Malwarebytes warns of sophisticated fake website scams pushing remote-access malware

Cybersecurity firm Malwarebytes uncovers a coordinated campaign using cloned trusted websites to distribute remote access malware via convincing fake app downloads, exploiting well-known brands like CNN, Avast and Stremio.

Malwarebytes has identified a new wave of download scams in which attackers copy well-known websites and use them to push fake free apps that actually install remote-access software on Windows devices. The pages are designed to look like trusted brands, including CNN, Avast and Stremio, and present visitors with a convincing prompt to download what appears to be an official application. According to Malwarebytes, the real goal is not to deliver the promised software but to place an attacker-controlled remote administration tool on the machine.

The security company said the campaign uses O&O Syspectr, a legitimate remote management product that has been digitally signed. In the wrong hands, that sort of software can let an intruder operate a victim’s computer from afar, run commands, add more programmes and browse files and other data. Malwarebytes said the false downloads tied to the CNN, Avast and Stremio lures all point to the same Syspectr account, which suggests a coordinated operation rather than isolated fraud.

The technique fits a wider pattern seen in recent Malwarebytes research. In other cases, the company has documented fake software download sites used to distribute malicious installers and separate scams in which bogus party invitations were used to persuade victims to install remote access tools such as ScreenConnect. The common thread is social engineering: attackers borrow the credibility of familiar brands or everyday invitations to convince users to run software that hands over control of their devices.

For users, the defence is straightforward but important. Malwarebytes says software should be downloaded only from the vendor’s official website, not from search ads or cloned pages that can appear highly polished. On Windows, users can also right-click a file, open Properties and check the Details tab for fields such as file description and product name to confirm whether a programme is what it claims to be. That extra step can help expose a Trojan horse before it is installed.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.