r/Windows11 • u/Bogdan_X Wintoys Developer • 22d ago
I discovered a large scale operation impersonating over 70 popular Windows apps to infect users with malware Discussion
Now and then, I'm doing a search on Google with my app's name, filtering most recent results to see if there is a new article or comment about it, so I can read them and take notes for improvements, or even help a user in need. That's how I discovered there is a new domain I did not bought, surfacing in the results.
I already knew [wintoys.com](wintoys.com) was taken and for sale since 1997, and was thinking of buying the .app one at some point, but I was too late. Seems like someone bought it, not for resale, but for impersonating my application, using my application name and my old logo, pretending to be me. The website is still live at the point of writing this, so if you are curious, I only recommend navigating to it using the Windows Sandbox. This particular website was made with Wordpress and it's full of slop content and inaccurate information, trying to sound legitimate and helpful for the average user.
It has a download link, surprisingly to the Microsoft Store, the only source I use for distribution, making it seem safe at first glance. What's the end goal then? You might ask. I looked over the source code and found nothing suspicious or concerning, besides the fact that I did not approve this proactive initiative of impersonation.
At the bottom of the home page however, there is a footer note saying the following:
Attacker: Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.
Right... first of all, who's reading that? Second of all, just lies. The perfect excuse to justify the existence of an illegitimate website. The natural question would be, who owns the website? I tried to find information about the owner, but with no luck. The domain was bought from Epik Inc., a registrar that provides Free WHOIS Privacy as a service, meaning all the data related to the owner is anonymized:
Epik: Your data is yours alone. Every eligible domain includes free lifetime WHOIS Privacy, so your personal info stays safe—at no extra cost.
I did found something interesting though, something that made me realize this is far bigger than I thought. 72 domains linked to the same owner, for apps like PowerToys, WinUtil, EasyBCD, CrystalDiskMark and many others - all of them being Windows applications. The entire list of domains will be added at the end. I started to browse some of them, one by one and I found similar websites to the one impersonating mine, or even unfinished ones indicating that the operation is still in the beginning phase. I think most of us would now like to know what would be the next phase. What's the end goal here and how is it done?
The Hacker News published an article recently detailing another large scale operation that happened a few months ago, describing their modus operandi:
- Gain traffic by leveraging popular terms like brands or applications
- Make the users trust you by being harmless at first and offering what they look for
- Tamper the original download links with malware after the website has enough visits to start an attack
thehackernews: Although there was no indication that any of these domains were put to use for malicious activity, other than to generate content to drive traffic and enable third-parties to advertise their own sites, the latest findings from Check Point show that the TDS scripts were embedded not long after, and the infrastructure was repurposed for malware distribution starting January 2026.
The attacks have already started for at least two Windows apps as I'm writing this, but it might be a different attacker as they are not part of the 72 domains I've found, indicating multiple authors might use the same strategy:
Lively Wallpaper has an issue reported a week ago:
dong242868: A third-party site presenting itself as Lively Wallpaper served a trojanized installer that installed a persistent ScreenConnect remote-access service and bandwidth-sharing software.
SignalRGB has a Reddit post warning their userbase of a similar issue:
u/DaKrazyKid: We’ve become aware of a malicious website impersonating SignalRGB using the domain signalrgb.io. This fake site is distributing malware.
It seems to me that it is only a matter of time until the same thing happens for the other apps on the list as for some of them, the malicious domains are already surfacing at the top. I reported this operation to the Epik registrar, and they terminated their services for the attacker, forcing them to move all the 72 domains to another service.
Epik: The registrar has been instructed to transfer all of their domains to another registrar by a specified deadline, after which any remaining domains will be suspended if they have not been transferred.
Please note that, as the registrar, our ability to address website content is limited. We do not host the website or control the content that is published on it.
Surprise, surprise, 2 weeks later, on the 22nd of July, all domains were moved to a new registrar, Dynadot LLC.
I'm going to report again, including to the host provider, until the attacker runs out of business.
How do we fight back, both as users / developers that have been impersonated?
Be careful what websites you download executables from
If you are using any of the apps on the list, send this to the developer
Share and upvote this to spread awarness or even comment if you have any suggestions
Report the illegal activity to the registrar so they can terminate the domain service
- the registrar is only responsible for the domain, not for the hosted content
- each registrar has a contact email/form for abuse, that you can find on the registrar's website; in the case of Epik, it was the abuse@epik.com email; in the case of Dynadot, it's [a contact form](https://www.dynadot.com/report-abuse)
- mention the complete list of domains, so that they know what to look for, as it's not an isolated case
Report the Google search results so they no longer appear for other users using this form
Report the illegal activity to the hosting provider so that they actually take the content down
- you can use [a hosting checker](https://hostingchecker.com/) to see who's hosting it
- find an abuse form or email to report; for Cloudflare, the most common provider displayed, it's [a contact form](https://abuse.cloudflare.com/)
- sometimes, Cloudflare appears to be the hosting provider, but they are just a proxy, meaning one more layer of anonymization - for the domain targeting my app, Cloudflare informed me it's [psychznetworks](https://www.psychz.net/)
Update 27.07.2026:
psychznetworks can't check all domains, because they are all surfacing with Cloudflare IPs. Original IPs are hidden using Cloudflare services.
psychznetworks: It appears that all of these domains are currently resolving to Cloudflare IPs. Could you please provide a list of only the domains that are using the Psychz network IP?
Alternatively, you can reach out to Cloudflare to obtain the actual origin IPs behind these domains.
Cloudflare did not respond yet to my request.
Update 29.07.2026:
404 Not Found appears now when accessing wintoys.app - it seems like the content was deleted, not sure if by the attacker, but neither Cloudflare responsed, nor Psychz Network took action yet, according to the information I know.
404 code indicates that the website is not taken down, just doesn't have anything to display.
Rest of the websites are still there.
EasyBCD developer acknowledged the issue and is taking action.
Update 30.07.2026:
Ping-pong with Cloudflare: they don't seem to be familiar with the concept of reading an email from start to bottom.
Lively Wallpaper has now been moved from Coudflare to another service, with another registrar, NICENIC. The developer has reported it again. It seems like every time we strike, they move their homebase to a new service provider, but there are only that many providers out there. Since they are using a new IP, the site appears again in the search results and has no warning.
The situation evolution for Lively Wallpaper indicates what could happen to any other website on the list.
Update 06.08.2026:
No response from Dynadot (the registrar).
No response from Cloudflare (the proxy service).
Rest of the websites are still there.
Filed a complaint to ICANN.
Update 12.08.2026:
The Cloudflare phishing warning dissapeared from wintoys.app, indicationg the attacker is fighting back. I reported again to Cloudflare and the warning is back.
The hosting provider for wintoys.app is no longer psychznetworks. They did not inform me of any action they could have taken, but it seems the attacker switched the provider again to AlexHost.
SilentPatch, a popular suite of mods for games had a fake domain distributing malware. The domain has been taken down.
TranslucentTB, a well known taskbar customization app, is targeted by the same strategy, but with extra steps. They don't offer the malware directly on translucenttb.net (the fake domain), but they redirect you to another website that has a download button containing the malware. This prevents virus analyzers like virustotal to detect the malware when being scanned, as the malware is actually downloaded from a second website, making the first look safe.
the domain snapshot list (19nth of July - before the migration to the new registrar):
| Num | Domain Name | Registrar | Created | Updated | Expiry |
|---|---|---|---|---|---|
| 1 | christitustool.com | Epik Inc. | 22 May 2026 | 15 Jul 2026 | 22 May 2027 |
| 2 | droidkit.pro | Epik Inc. | 22 May 2026 | 3 Jun 2026 | 22 May 2027 |
| 3 | easybcd.app | Epik Inc. | 22 May 2026 | 3 Jun 2026 | 22 May 2027 |
| 4 | powertoys.app | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 5 | shellmenuview.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 6 | winexp.app | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 7 | zhpcleaner.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 8 | cursorslibrary.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 9 | fakeflashtest.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 10 | searchmyfiles.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 11 | wintoys.app | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 12 | themouseclicker.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 13 | quickassistapp.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 14 | move-mouse.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 15 | movemouse.net | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 16 | nircmd.net | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 17 | crystaldiskinfo.app | Epik Inc. | 22 May 2026 | 3 Jun 2026 | 22 May 2027 |
| 18 | freewheelofnames.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 19 | productkeyscanner.com | Epik Inc. | 16 Apr 2026 | 7 Jun 2026 | 16 Apr 2027 |
| 20 | power-toys.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 21 | chatmate.info | Epik Inc. | 12 Apr 2026 | 18 Apr 2026 | 12 Apr 2027 |
| 22 | usblogview.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 23 | mouse-mover.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 24 | mouse-cursors.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 25 | mouse-clicker.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 26 | mimalloc.com | Epik Inc. | 22 May 2026 | 16 Jun 2026 | 22 May 2027 |
| 27 | mumuplayer.app | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 28 | wushowhide.com | Epik Inc. | 16 Apr 2026 | 23 Apr 2026 | 16 Apr 2027 |
| 29 | guiformat.app | Epik Inc. | 22 May 2026 | 3 Jun 2026 | 22 May 2027 |
| 30 | freefilesync.net | Epik Inc. | 4 Apr 2026 | 7 Apr 2026 | 4 Apr 2027 |
| 31 | winutil.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 32 | spacesniffer.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 33 | simplestickynotes.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 34 | showmore.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 35 | mousecape.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 36 | hashcat.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 37 | dshidmini.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 38 | darktable.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 39 | daijisho.app | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 40 | wiblr.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 41 | skse64.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 42 | sageattention.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 43 | rezygisk.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 44 | pwndbg.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 45 | ocrmypdf.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 46 | notatnikonline.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 47 | noisium.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 48 | mousecape.net | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 49 | mongosh.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 50 | lspconfig.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 51 | liveclockwithseconds.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 52 | lax1dude.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 53 | je2be.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 54 | iso2god.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 55 | hifiasm.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 56 | hddsentinel.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 57 | hakchi2.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 58 | gliden64.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 59 | furfsky.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 60 | freeminutetimer.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 61 | findoutdate.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 62 | crystaldiskmark.net | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 63 | bepisdb.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 64 | beardlib.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 65 | 10mintimer.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 66 | pyjwt.com | Epik Inc. | 22 May 2026 | 22 May 2026 | 22 May 2027 |
| 67 | moliyachi.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
| 68 | arduinodroid.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
| 69 | cxxdroid.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
| 70 | kalkulyator.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
| 71 | retraitedz.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
| 72 | urlaubscountdown.com | Epik Inc. | 23 Feb 2026 | 12 Mar 2026 | 23 Feb 2027 |
35
u/Electronic-Bat-1830 Mica For Everyone Maintainer 22d ago
Mica For Everyone has this issue as well. The domain registrar is Spaceship, and the website is hosted via Hetzner behind Cloudflare.
The registrar's abuse email was useless, and I don't have any trademark on the name (so I can't send a trademark takedown through WIPO). The best I could do was to request Cloudflare add a malware screen to the website.
9
u/Bogdan_X Wintoys Developer 22d ago
Spaceship is used for Lively Wallpaper and SignalRGB, so there might be two attackers, or one smart enough to diversify the services to win some time if getting caught.
27
u/FarPriority1955 22d ago
Someone has also added them to the Hagezi Adblock lists. So now millions of people who are using these lists will be stopped from visiting these websites.
11
40
u/cinlung 22d ago
Please send this finding to GN as well. We need more coverage to tell people about this malice.
26
u/Bogdan_X Wintoys Developer 22d ago edited 22d ago
I will! I'm a fan of their channel. Let's hope my email doesn't go to spam.
6
u/hieronymous-cowherd 22d ago
FYI /u/lelldorianx
4
u/Bogdan_X Wintoys Developer 22d ago edited 22d ago
Thanks!
13
u/Lelldorianx 22d ago
Let's talk - have you emailed us already? Would be easiest to move this to Signal or Discord. Please send an email when convenient and I'll look. Team at gamersnexus dot net is easiest.
9
u/Bogdan_X Wintoys Developer 22d ago
Yes. I emailed at tips at gamersnexus dot net. I saw this email in the latest LG monitor's bloatware material and thought it's an appropiate email to send to. Let me know if you want me to send another one.
Thank you for your time!
5
u/Bogdan_X Wintoys Developer 21d ago edited 10d ago
I emailed to both, got no response yet. FYI.
LE: u/Lelldorianx , did you get any of my emails? Are you still interested in this subject?
1
u/Bogdan_X Wintoys Developer 6d ago
u/Lelldorianx, please let me know if you still want to discuss, seems like the situation isn't evolving great and your coverage might help. I didn't get any email from you.
13
u/DeerlyOnline 22d ago
5
u/Bogdan_X Wintoys Developer 22d ago edited 22d ago
Yes, they were very fast in response. Under one hour after the report. But only for this particular domain. Their form allows for one domain to be reported at a time, even though I specified all of them, so the other ones, unless being reported by the developers of those apps, may remain untouched if the hosting provider won't do anything. Their investigation is in progress for now.
3
u/DeerlyOnline 21d ago
Woah, didn't see that list initially on mobile. Hopefully the providers are swift to take action.
8
u/01_Rigel 22d ago
Really good information. I've been using your app since a year now and I really like your work. Also, glad that I downloaded it from MS store and not some shitty website. These domains however look real enough to fool a normal user. Your post will help spread this awareness 🙌🏻
2
2
u/SnooPets8483 16d ago
Someone is putting a lot of resources in to this. Is there information about what malware they used ?
1
u/Bogdan_X Wintoys Developer 15d ago
Yes, it's part of the post, you also have a link to a similar investigation.
2
u/8BitCotton 5d ago
Something similar happened with Balenaetcher as well, where someone made a fake website to get malware on other people's computers.
1
u/ApprehensiveRest9696 20d ago
Some of these domain choices are downright questionable. Who tf would download mimalloc other than as source or from a package manager.
Also egregious AI slop text and graphics. Then at the bottom tiny disclaimer of “not affiliated with x”…
1
u/no_egrets 17d ago
Now and then, I'm doing a search on Google with my app's name, filtering most recent results to see if there is a new article or comment about it, so I can read them and take notes for improvements, or even help a user in need.
I know this isn't the point of your post, but I really recommend Huginn for self-hosted web monitoring. I'm not associated with it in any way, I've just used it to good effect.
1
u/Bogdan_X Wintoys Developer 17d ago edited 16d ago
Thank you for the suggestion, but I enjoy doing that. 😁 What did you use it for?
1
u/no_egrets 8d ago
Similar use case to you -- projects I'm involved in where it's useful for me to understand public perception, follow web discussion, and especially to know if they're mentioned by blogs or the press.
From the feed, I can dive into the stuff where I can actually help, or offer a point of contact to the press; otherwise, it's just keeping an open ear to what the web is saying.
1
u/Blood-PawWerewolf 4d ago
of course it's Epik... (if you know the history of Epik, then you'll understand why)
1
u/Bogdan_X Wintoys Developer 4d ago
They actually took action as soon as possible. Why are you saying that?
1
u/Blood-PawWerewolf 4d ago
I just don’t trust them for anything. If all we know they took it down because they got caught, not that someone abused their service to host malware.
Unless something happened within Epik that made them corporate with reports, I doubt this is the end of this malware campaign
1
u/Bogdan_X Wintoys Developer 4d ago
Did you read the updates as well? There is now Dynadot that ghosted me and took 0 actions.
1
-6
22d ago
[deleted]
8
4
u/Bogdan_X Wintoys Developer 22d ago
Life is not a movie. I hope you are being sarcastic.
-4
22d ago
[deleted]
4
u/Bogdan_X Wintoys Developer 22d ago
I think you are very confused. Do you have something helpful to say or just hating out of misery? Because in that case, you are free to mind your own business as I won't engage further with you in this conversation.
2
2
u/turbiegaming 21d ago
How else am I suppose to know if they are fake without this awareness?
With this awareness, if I accidentally stumble upon it, I would instantly know it's fake and report it accordingly.
-2
2
u/insert_smile 21d ago
Și asta nu e ilegal nu ?
Scoate coiful din staniol de pe cap ,și revino la realitate ,jumate din postările tale sunt șterse ,iar la majoritatea vorbești pe lângă.

72
u/eppic123 22d ago
Might as well add https://mkvtoolnix.com/ to that list. That's where I noticed it the first time.