Hover over the download button on a site offering Counter-Strike and the browser shows you a genuine Steam Store address. Click it and Steam never opens. That gap between what the link says and where it goes is the trick behind 41 fake download sites documented by Malwarebytes, and it defeats the safety check most people are taught to run.
The sites impersonate games and everyday Windows software, from Counter-Strike, Fallout and The Witcher to VLC, 7-Zip, VMware and Foxit PDF. The branding changes from page to page. The destination does not. Whatever the visitor came for, they are pushed toward the same installer for a program called Download Studio.
A link that lies on hover
On the Counter-Strike page the download button really does contain a legitimate Steam URL, which is what the browser displays. JavaScript on the page then handles the click separately, cancels the navigation the visitor expected, and sends them through an affiliate redirect instead.
A few of the lures collapse if you know the product. GTA 6 PLAY offers a PC download of Grand Theft Auto VI, which Rockstar currently lists for PlayStation 5 and Xbox Series X|S with a release date of November 19, 2026 and has not announced for PC. The software pages are harder to catch: a fake VLC page puts a real VideoLAN address in its button, correctly names VideoLAN as the source, and cites VLC 3.0.23, which was VideoLAN's current release at the time of the research. Everything shown is accurate. The click handler overrides all of it.
A valid signature proves the wrong thing
The VLC lure even recommends checking the installer's digital signature before running it. It passes: the 73 MB sample Malwarebytes examined is validly signed by Grand Media, TOV. A signature tells you who signed a file and that its contents have not been altered since. It does not tell you the file is the program you meant to download, and Microsoft's own Authenticode documentation draws the same distinction between publisher identity and trustworthiness. A visitor can follow the standard advice exactly, see a valid signature from a real company, and still end up with software they never asked for.
Why Download Studio's updater matters
Malwarebytes is careful on this point and so are we: its analysis did not establish that Download Studio is malware, and there is no evidence the installer in this campaign is malicious. What it establishes is deceptive funnelling, with affiliate tracking in the redirect pointing to a commercial motive.
The history is why it still matters. In 2020, researchers at Avast found Download Studio's automatic updates had been used to silently distribute FakeMBAM, a backdoor disguised as a Malwarebytes installer, delivered exactly as legitimate updates were; the persistent payloads Avast observed were cryptocurrency miners. Avast's research also named Grand Media, TOV among the companies associated with those applications, the same name on today's signature. The current installer switches its automatic updater on.
Check the Details tab, not just the signature
Right-click the file, choose Properties, and open the Details tab. For the sample examined, File description and Product name read Download Studio and Original filename is DS-Setup.exe. If the button said VLC and the file says otherwise, that is your answer. A publisher controls those fields, so treat a match as one signal rather than proof, and take software from the developer's own site or a trusted store.
This shape keeps recurring, and signed, legitimate-looking software is what makes it work. We covered fake CNN and Avast pages pushing a signed remote management tool earlier this month, and fake Mac download pages that hide from scanners before that.
Defanged indicators from the Malwarebytes report. Installer SHA-256: 9a3f6e69c12cb814c45862219ecb17e9ab7744877c9da1c49f3ea046437f8fca (DS-Setup.exe). Infrastructure: r.byteengineering[.]net, apis.downloadstud[.]io, downloadstudio[.]net. Lures include gta6-play[.]ru, csgodownload[.]ru, vlcmp[.]ru and getavast[.]ru; all 41 are listed in the original report.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.