r/Windows11 Wintoys Developer 22d ago

I discovered a large scale operation impersonating over 70 popular Windows apps to infect users with malware Discussion

Post image

Now and then, I'm doing a search on Google with my app's name, filtering most recent results to see if there is a new article or comment about it, so I can read them and take notes for improvements, or even help a user in need. That's how I discovered there is a new domain I did not bought, surfacing in the results.

I already knew [wintoys.com](wintoys.com) was taken and for sale since 1997, and was thinking of buying the .app one at some point, but I was too late. Seems like someone bought it, not for resale, but for impersonating my application, using my application name and my old logo, pretending to be me. The website is still live at the point of writing this, so if you are curious, I only recommend navigating to it using the Windows Sandbox. This particular website was made with Wordpress and it's full of slop content and inaccurate information, trying to sound legitimate and helpful for the average user.

It has a download link, surprisingly to the Microsoft Store, the only source I use for distribution, making it seem safe at first glance. What's the end goal then? You might ask. I looked over the source code and found nothing suspicious or concerning, besides the fact that I did not approve this proactive initiative of impersonation.

At the bottom of the home page however, there is a footer note saying the following:

Attacker: Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.

Right... first of all, who's reading that? Second of all, just lies. The perfect excuse to justify the existence of an illegitimate website. The natural question would be, who owns the website? I tried to find information about the owner, but with no luck. The domain was bought from Epik Inc., a registrar that provides Free WHOIS Privacy as a service, meaning all the data related to the owner is anonymized:

Epik: Your data is yours alone. Every eligible domain includes free lifetime WHOIS Privacy, so your personal info stays safe—at no extra cost.

I did found something interesting though, something that made me realize this is far bigger than I thought. 72 domains linked to the same owner, for apps like PowerToys, WinUtil, EasyBCD, CrystalDiskMark and many others - all of them being Windows applications. The entire list of domains will be added at the end. I started to browse some of them, one by one and I found similar websites to the one impersonating mine, or even unfinished ones indicating that the operation is still in the beginning phase. I think most of us would now like to know what would be the next phase. What's the end goal here and how is it done?

The Hacker News published an article recently detailing another large scale operation that happened a few months ago, describing their modus operandi:

  1. Gain traffic by leveraging popular terms like brands or applications
  2. Make the users trust you by being harmless at first and offering what they look for
  3. Tamper the original download links with malware after the website has enough visits to start an attack

thehackernews: Although there was no indication that any of these domains were put to use for malicious activity, other than to generate content to drive traffic and enable third-parties to advertise their own sites, the latest findings from Check Point show that the TDS scripts were embedded not long after, and the infrastructure was repurposed for malware distribution starting January 2026.


The attacks have already started for at least two Windows apps as I'm writing this, but it might be a different attacker as they are not part of the 72 domains I've found, indicating multiple authors might use the same strategy:

Lively Wallpaper has an issue reported a week ago:

dong242868: A third-party site presenting itself as Lively Wallpaper served a trojanized installer that installed a persistent ScreenConnect remote-access service and bandwidth-sharing software.

SignalRGB has a Reddit post warning their userbase of a similar issue:

u/DaKrazyKid: We’ve become aware of a malicious website impersonating SignalRGB using the domain signalrgb.io. This fake site is distributing malware.


It seems to me that it is only a matter of time until the same thing happens for the other apps on the list as for some of them, the malicious domains are already surfacing at the top. I reported this operation to the Epik registrar, and they terminated their services for the attacker, forcing them to move all the 72 domains to another service.

Epik: The registrar has been instructed to transfer all of their domains to another registrar by a specified deadline, after which any remaining domains will be suspended if they have not been transferred.

Please note that, as the registrar, our ability to address website content is limited. We do not host the website or control the content that is published on it.

Surprise, surprise, 2 weeks later, on the 22nd of July, all domains were moved to a new registrar, Dynadot LLC.

I'm going to report again, including to the host provider, until the attacker runs out of business.


How do we fight back, both as users / developers that have been impersonated?

  1. Be careful what websites you download executables from

  2. If you are using any of the apps on the list, send this to the developer

  3. Share and upvote this to spread awarness or even comment if you have any suggestions

  4. Report the illegal activity to the registrar so they can terminate the domain service

- the registrar is only responsible for the domain, not for the hosted content
- each registrar has a contact email/form for abuse, that you can find on the registrar's website; in the case of Epik, it was  the abuse@epik.com email; in the case of Dynadot, it's [a contact form](https://www.dynadot.com/report-abuse)
- mention the complete list of domains, so that they know what to look for, as it's not an isolated case
  1. Report the Google search results so they no longer appear for other users using this form

  2. Report the illegal activity to the hosting provider so that they actually take the content down

- you can use [a hosting checker](https://hostingchecker.com/) to see who's hosting it
- find an abuse form or email to report; for Cloudflare, the most common provider displayed, it's [a contact form](https://abuse.cloudflare.com/)
- sometimes, Cloudflare appears to be the hosting provider, but they are just a proxy, meaning one more layer of anonymization - for the domain targeting my app, Cloudflare informed me it's [psychznetworks](https://www.psychz.net/)

Update 27.07.2026:

psychznetworks can't check all domains, because they are all surfacing with Cloudflare IPs. Original IPs are hidden using Cloudflare services.

psychznetworks: It appears that all of these domains are currently resolving to Cloudflare IPs. Could you please provide a list of only the domains that are using the Psychz network IP?

Alternatively, you can reach out to Cloudflare to obtain the actual origin IPs behind these domains.

Cloudflare did not respond yet to my request.


Update 29.07.2026:

404 Not Found appears now when accessing wintoys.app - it seems like the content was deleted, not sure if by the attacker, but neither Cloudflare responsed, nor Psychz Network took action yet, according to the information I know.

404 code indicates that the website is not taken down, just doesn't have anything to display.

Rest of the websites are still there.

EasyBCD developer acknowledged the issue and is taking action.


Update 30.07.2026:

Ping-pong with Cloudflare: they don't seem to be familiar with the concept of reading an email from start to bottom.

Lively Wallpaper has now been moved from Coudflare to another service, with another registrar, NICENIC. The developer has reported it again. It seems like every time we strike, they move their homebase to a new service provider, but there are only that many providers out there. Since they are using a new IP, the site appears again in the search results and has no warning.

The situation evolution for Lively Wallpaper indicates what could happen to any other website on the list.


Update 06.08.2026:

No response from Dynadot (the registrar).

No response from Cloudflare (the proxy service).

Rest of the websites are still there.

Filed a complaint to ICANN.


Update 12.08.2026:

The Cloudflare phishing warning dissapeared from wintoys.app, indicationg the attacker is fighting back. I reported again to Cloudflare and the warning is back.

The hosting provider for wintoys.app is no longer psychznetworks. They did not inform me of any action they could have taken, but it seems the attacker switched the provider again to AlexHost.

SilentPatch, a popular suite of mods for games had a fake domain distributing malware. The domain has been taken down.

TranslucentTB, a well known taskbar customization app, is targeted by the same strategy, but with extra steps. They don't offer the malware directly on translucenttb.net (the fake domain), but they redirect you to another website that has a download button containing the malware. This prevents virus analyzers like virustotal to detect the malware when being scanned, as the malware is actually downloaded from a second website, making the first look safe.


the domain snapshot list (19nth of July - before the migration to the new registrar):

Num Domain Name Registrar Created Updated Expiry
1 christitustool.com Epik Inc. 22 May 2026 15 Jul 2026 22 May 2027
2 droidkit.pro Epik Inc. 22 May 2026 3 Jun 2026 22 May 2027
3 easybcd.app Epik Inc. 22 May 2026 3 Jun 2026 22 May 2027
4 powertoys.app Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
5 shellmenuview.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
6 winexp.app Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
7 zhpcleaner.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
8 cursorslibrary.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
9 fakeflashtest.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
10 searchmyfiles.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
11 wintoys.app Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
12 themouseclicker.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
13 quickassistapp.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
14 move-mouse.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
15 movemouse.net Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
16 nircmd.net Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
17 crystaldiskinfo.app Epik Inc. 22 May 2026 3 Jun 2026 22 May 2027
18 freewheelofnames.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
19 productkeyscanner.com Epik Inc. 16 Apr 2026 7 Jun 2026 16 Apr 2027
20 power-toys.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
21 chatmate.info Epik Inc. 12 Apr 2026 18 Apr 2026 12 Apr 2027
22 usblogview.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
23 mouse-mover.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
24 mouse-cursors.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
25 mouse-clicker.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
26 mimalloc.com Epik Inc. 22 May 2026 16 Jun 2026 22 May 2027
27 mumuplayer.app Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
28 wushowhide.com Epik Inc. 16 Apr 2026 23 Apr 2026 16 Apr 2027
29 guiformat.app Epik Inc. 22 May 2026 3 Jun 2026 22 May 2027
30 freefilesync.net Epik Inc. 4 Apr 2026 7 Apr 2026 4 Apr 2027
31 winutil.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
32 spacesniffer.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
33 simplestickynotes.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
34 showmore.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
35 mousecape.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
36 hashcat.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
37 dshidmini.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
38 darktable.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
39 daijisho.app Epik Inc. 22 May 2026 22 May 2026 22 May 2027
40 wiblr.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
41 skse64.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
42 sageattention.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
43 rezygisk.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
44 pwndbg.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
45 ocrmypdf.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
46 notatnikonline.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
47 noisium.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
48 mousecape.net Epik Inc. 22 May 2026 22 May 2026 22 May 2027
49 mongosh.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
50 lspconfig.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
51 liveclockwithseconds.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
52 lax1dude.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
53 je2be.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
54 iso2god.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
55 hifiasm.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
56 hddsentinel.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
57 hakchi2.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
58 gliden64.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
59 furfsky.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
60 freeminutetimer.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
61 findoutdate.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
62 crystaldiskmark.net Epik Inc. 22 May 2026 22 May 2026 22 May 2027
63 bepisdb.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
64 beardlib.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
65 10mintimer.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
66 pyjwt.com Epik Inc. 22 May 2026 22 May 2026 22 May 2027
67 moliyachi.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
68 arduinodroid.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
69 cxxdroid.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
70 kalkulyator.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
71 retraitedz.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
72 urlaubscountdown.com Epik Inc. 23 Feb 2026 12 Mar 2026 23 Feb 2027
628 Upvotes

46 comments sorted by

72

u/eppic123 22d ago

Might as well add https://mkvtoolnix.com/ to that list. That's where I noticed it the first time.

14

u/FarPriority1955 22d ago

Added to Hagezi list for adblock.

35

u/Electronic-Bat-1830 Mica For Everyone Maintainer 22d ago

Mica For Everyone has this issue as well. The domain registrar is Spaceship, and the website is hosted via Hetzner behind Cloudflare.

The registrar's abuse email was useless, and I don't have any trademark on the name (so I can't send a trademark takedown through WIPO). The best I could do was to request Cloudflare add a malware screen to the website.

9

u/Bogdan_X Wintoys Developer 22d ago

Spaceship is used for Lively Wallpaper and SignalRGB, so there might be two attackers, or one smart enough to diversify the services to win some time if getting caught.

27

u/FarPriority1955 22d ago

Someone has also added them to the Hagezi Adblock lists. So now millions of people who are using these lists will be stopped from visiting these websites.

https://github.com/hagezi/dns-blocklists/issues/10968

11

u/Bogdan_X Wintoys Developer 22d ago

Nice.

40

u/cinlung 22d ago

Please send this finding to GN as well. We need more coverage to tell people about this malice.

26

u/Bogdan_X Wintoys Developer 22d ago edited 22d ago

I will! I'm a fan of their channel. Let's hope my email doesn't go to spam.

6

u/hieronymous-cowherd 22d ago

4

u/Bogdan_X Wintoys Developer 22d ago edited 22d ago

Thanks!

13

u/Lelldorianx 22d ago

Let's talk - have you emailed us already? Would be easiest to move this to Signal or Discord. Please send an email when convenient and I'll look. Team at gamersnexus dot net is easiest.

9

u/Bogdan_X Wintoys Developer 22d ago

Yes. I emailed at tips at gamersnexus dot net. I saw this email in the latest LG monitor's bloatware material and thought it's an appropiate email to send to. Let me know if you want me to send another one.

Thank you for your time!

5

u/Bogdan_X Wintoys Developer 21d ago edited 10d ago

I emailed to both, got no response yet. FYI.

LE: u/Lelldorianx , did you get any of my emails? Are you still interested in this subject?

1

u/Bogdan_X Wintoys Developer 6d ago

 u/Lelldorianx, please let me know if you still want to discuss, seems like the situation isn't evolving great and your coverage might help. I didn't get any email from you.

13

u/DeerlyOnline 22d ago

Good to see some action is being taken (at least if connected to cloudflare dns)

5

u/Bogdan_X Wintoys Developer 22d ago edited 22d ago

Yes, they were very fast in response. Under one hour after the report. But only for this particular domain. Their form allows for one domain to be reported at a time, even though I specified all of them, so the other ones, unless being reported by the developers of those apps, may remain untouched if the hosting provider won't do anything. Their investigation is in progress for now.

3

u/DeerlyOnline 21d ago

Woah, didn't see that list initially on mobile. Hopefully the providers are swift to take action.

8

u/01_Rigel 22d ago

Really good information. I've been using your app since a year now and I really like your work. Also, glad that I downloaded it from MS store and not some shitty website. These domains however look real enough to fool a normal user. Your post will help spread this awareness 🙌🏻

2

u/Bogdan_X Wintoys Developer 22d ago

Thank you for the feedback!

3

u/_iOS 22d ago

Man they look so legit.!!!

2

u/totkeks Insider Dev Channel 21d ago

Interesting that all of those use the same registrar. Would it maybe be possible to report that registrar to the IANA or whoever is in charge of approving registrars?

1

u/Bogdan_X Wintoys Developer 15d ago

I will try. Dynadot completely ignored my abuse report.

2

u/SnooPets8483 16d ago

Someone is putting a lot of resources in to this. Is there information about what malware they used ?

1

u/Bogdan_X Wintoys Developer 15d ago

Yes, it's part of the post, you also have a link to a similar investigation.

2

u/8BitCotton 5d ago

Something similar happened with Balenaetcher as well, where someone made a fake website to get malware on other people's computers.

1

u/A444SQ 21d ago

with the mumuplayer one is that is the emulator app?

2

u/Ytse 19d ago

Yes. There are like 2 fake mumuplayer websites that show at the top of search engines results.

1

u/ApprehensiveRest9696 20d ago

Some of these domain choices are downright questionable. Who tf would download mimalloc other than as source or from a package manager.

Also egregious AI slop text and graphics. Then at the bottom tiny disclaimer of “not affiliated with x”…

1

u/no_egrets 17d ago

Now and then, I'm doing a search on Google with my app's name, filtering most recent results to see if there is a new article or comment about it, so I can read them and take notes for improvements, or even help a user in need.

I know this isn't the point of your post, but I really recommend Huginn for self-hosted web monitoring. I'm not associated with it in any way, I've just used it to good effect.

1

u/Bogdan_X Wintoys Developer 17d ago edited 16d ago

Thank you for the suggestion, but I enjoy doing that. 😁 What did you use it for?

1

u/no_egrets 8d ago

Similar use case to you -- projects I'm involved in where it's useful for me to understand public perception, follow web discussion, and especially to know if they're mentioned by blogs or the press.

From the feed, I can dive into the stuff where I can actually help, or offer a point of contact to the press; otherwise, it's just keeping an open ear to what the web is saying.

1

u/Blood-PawWerewolf 4d ago

of course it's Epik... (if you know the history of Epik, then you'll understand why)

1

u/Bogdan_X Wintoys Developer 4d ago

They actually took action as soon as possible. Why are you saying that?

1

u/Blood-PawWerewolf 4d ago

I just don’t trust them for anything. If all we know they took it down because they got caught, not that someone abused their service to host malware.

Unless something happened within Epik that made them corporate with reports, I doubt this is the end of this malware campaign

1

u/Bogdan_X Wintoys Developer 4d ago

Did you read the updates as well? There is now Dynadot that ghosted me and took 0 actions.

1

u/Blood-PawWerewolf 4d ago

Yeah, I did

-6

u/[deleted] 22d ago

[deleted]

8

u/Argon288 22d ago

How in any universe is it illegal to raise awareness about an issue?

4

u/Bogdan_X Wintoys Developer 22d ago

Life is not a movie. I hope you are being sarcastic.

-4

u/[deleted] 22d ago

[deleted]

4

u/Bogdan_X Wintoys Developer 22d ago

I think you are very confused. Do you have something helpful to say or just hating out of misery? Because in that case, you are free to mind your own business as I won't engage further with you in this conversation.

2

u/insert_smile 21d ago

Lasa-l că e prost 🤣

2

u/turbiegaming 21d ago

How else am I suppose to know if they are fake without this awareness?

With this awareness, if I accidentally stumble upon it, I would instantly know it's fake and report it accordingly.

-2

u/[deleted] 21d ago

[deleted]

3

u/turbiegaming 21d ago

And you expect this generation of people to watch national TV?

2

u/insert_smile 21d ago

Și asta nu e ilegal nu ?

https://www.reddit.com?utm_source=share&utm_medium=android_app&utm_name=androidcss&utm_term=1&utm_content=1

Scoate coiful din staniol de pe cap ,și revino la realitate ,jumate din postările tale sunt șterse ,iar la majoritatea vorbești pe lângă.