VYPR
researchPublished Aug 19, 2026· 1 source

Deceptive Download Sites Trick Users with Fake Links to Push 'Download Studio' Installer

A network of 41 websites impersonates popular software and games, using deceptive tactics to redirect users to install 'Download Studio' instead of the advertised products.

Security researchers have uncovered a sophisticated network of 41 deceptive websites designed to lure unsuspecting users into downloading unwanted software. These sites meticulously impersonate popular games and Windows applications, including titles like Counter-Strike, Fallout, Roblox, PUBG, and The Witcher, as well as essential software such as VLC Media Player, 7-Zip, and VMware. They employ convincing branding, accurate product information, and even display genuine download links to build trust.

The core of the deception lies in how the download links function. While hovering over a download button might reveal a legitimate URL for the intended software (e.g., a Steam Store link for Counter-Strike), clicking the button does not initiate the expected download. Instead, malicious JavaScript embedded in the page intercepts the click. This script cancels the intended navigation and redirects the user through an affiliate link, ultimately leading them to download and install a program called 'Download Studio'.

This technique exploits a common user habit: inspecting links by hovering before clicking. The websites leverage this by presenting a reassuring, authentic destination URL to the user's browser. However, the actual click event is handled separately by JavaScript, which bypasses the displayed link entirely. This creates a false sense of security, as the user sees a trusted URL but is ultimately sent to an entirely different, unintended destination.

Across the network of 41 sites, the advertised software varies, but the ultimate goal remains the same: pushing the 'Download Studio' installer. Even pages advertising legitimate applications like VLC Media Player use the same deceptive method. They might display the correct download address and version number for VLC, but the click handler redirects users to Download Studio. This tactic is also employed on pages for less common software, and even on those promoting non-existent products, such as a PC version of Grand Theft Auto VI, which has not yet been announced for PC release.

Adding another layer of deception, some of these sites even provide misleading advice on verifying software integrity. For instance, a fake VLC page might suggest checking the installer's digital signature. The 'Download Studio' installer is indeed validly signed by 'Grand Media, TOV', meaning a user following this advice would see a valid signature, further reinforcing the false impression that they have downloaded the correct software. However, a valid signature only confirms the publisher and file integrity, not that the downloaded program is the one the user intended to acquire.

The software delivered by this campaign is a roughly 73 MB Windows installer for 'Download Studio'. Analysis indicates that upon installation, Download Studio launches its own interface, registers torrent associations, and includes an option to become the default torrent client. Its automatic updater is also enabled. While the analysis did not definitively classify 'Download Studio' itself as malware, the campaign's clear intent is to trick users seeking legitimate software into installing an unwanted program through deceptive means.

This campaign highlights a growing trend of sophisticated social engineering tactics used to distribute potentially unwanted software (PUPs) or other malicious payloads. By combining deceptive website design, misleading link behavior, and even falsified security advice, these sites effectively funnel users towards an unintended installation, demonstrating the evolving challenges in online security and user awareness.

Synthesized by Vypr AI