A network of 41 websites impersonated popular games and Windows software to funnel visitors toward installing Download Studio, using deceptive click handling, affiliate redirects, and convincing fake download pages. The campaign included genuine-looking links, valid signatures, and prior abuse history tied to Download Studio’s updater, including FakeMBAM distribution by Avast-reported attackers. #DownloadStudio #FakeMBAM #GrandMediaTOV #VideoLAN #Steam #Rockstar
Keypoints
- 41 websites were found impersonating games and Windows applications to push users toward Download Studio.
- The pages used real product information, genuine developer resources, and even legitimate-looking download URLs to appear trustworthy.
- Click behavior was altered with JavaScript so hovering showed a safe destination, but clicking redirected users elsewhere through affiliate tracking.
- Targets included Counter-Strike, Half-Life, Fallout, Roblox, PUBG, The Witcher, VLC, 7-Zip, Paint.NET, VMware, Total Commander, Foxit PDF, and others.
- The delivered installer was a roughly 73 MB Windows package for Download Studio, signed by Grand Media, TOV, and it validated successfully.
- Download Studio’s updater has historical abuse: Avast previously observed it distributing FakeMBAM, a backdoor disguised as Malwarebytes.
- The campaign appears to have a commercial motive, and the sites used bait-and-switch tactics rather than directly delivering the advertised software.
MITRE Techniques
- [T1204.001 ] User Execution: Malicious Link – Victims are induced to click deceptive download buttons that appear legitimate but redirect to Download Studio through hidden click handling (‘the script cancels the expected navigation and sends the visitor through an affiliate redirect’).
- [T1036 ] Masquerading – The sites and installers impersonate trusted games and software, including VLC, Counter-Strike, and Windows utilities, to look authentic (‘advertise everything from Counter-Strike… to VLC, 7-Zip, Paint.NET’).
- [T1584.001 ] Compromise Infrastructure: Domains – A large set of lookalike domains was used to host fake download pages and redirects (’41 websites… downloadstudio[.]net … csgodownload[.]ru … vlcmp[.]ru’).
- [T1195 ] Supply Chain Compromise – The campaign abuses the software distribution flow by substituting the intended download with a different installer (‘the advertised software is the lure. Installing Download Studio is the destination’).
- [T1553.002 ] Subvert Trust Controls: Code Signing – The installer is validly signed, which can mislead users into trusting the file (‘The sample we examined is validly signed by Grand Media, TOV’).
- [T1105 ] Ingress Tool Transfer – The maliciously misleading websites deliver a Windows installer to the victim system (‘the sample delivered during our research is a roughly 73 MB Windows installer’).
- [T1053 ] Scheduled Task/Job: Automatic Update or equivalent updater mechanism – The installer enables automatic updating, which is notable because updates were previously abused to deliver FakeMBAM (‘the installation also enables its automatic updater’).
Indicators of Compromise
- [SHA-256 ] Download Studio installer sample – 9a3f6e69c12cb814c45862219ecb17e9ab7744877c9da1c49f3ea046437f8fca (DS-Setup.exe)
- [Domains ] Download Studio infrastructure and redirect endpoints – r.byteengineering[.]net, apis.downloadstud[.]io, downloadstudio[.]net, dstudio[.]app, getdownloadstudio[.]net
- [Domains ] Fake lure sites for games and software – csgodownload[.]ru, gta6-play[.]ru, halflife-play[.]ru, roblox-play[.]ru, vlcmp[.]ru
- [Domains ] Fake lure sites for utilities and security tools – get7zip[.]ru, getavast[.]ru, getrecuva[.]ru, getvmware[.]ru, foxitpdf[.]ru
- [File names ] Download Studio installer artifact – DS-Setup.exe