Hover over the link, read the address your browser shows in the corner, and decide from there. I have given you that advice on this blog more than once, and I would like to take part of it back. It was good advice. Unfortunately it has quietly stopped being reliable on its own, and a campaign documented in August 2026 shows exactly how.
What broke
Malwarebytes Labs published an analysis of 41 deceptive download sites on 19 August 2026. The sites impersonate popular games and free Windows software. On several of them, the download button contains a genuine address, a real Steam or VideoLAN link, so your browser truthfully reports a legitimate destination when you hover over it.
Then you click, and you go somewhere else entirely.
Malwarebytes put it in one line: "The link looks safe when you hover, but the click says otherwise."
store.steampowered.com/…the real address sitting inside the buttonan affiliate redirect →where the page's own script actually sends youHow is that even possible?
A link on a web page has an address written into it. That written address is what your browser reads out when you hover, and what it copies when you right-click and choose "copy link address". It is completely honest about what is written there.
But a click is a separate event, and a page can run its own code the moment you click. Describing the fake Counter-Strike page, Malwarebytes writes that "the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it. But JavaScript on the page handles the click separately." The script cancels the normal navigation and sends the browser somewhere of its own choosing instead.
Where all 41 sites lead
The brands used as bait are exactly the ones people search for when they want something free and familiar: VLC, 7-Zip, Paint.NET, VMware, Total Commander, Foxit PDF, AIMP, Recuva, and games including Counter-Strike, Roblox, Fallout, PUBG and The Witcher. It's the same bait as the fake game clients that ranked at the top of Google, with a sneakier button.
All of them funnel to the same thing: a product called Download Studio, roughly 73 MB, distributed as DS-Setup.exe, and validly code-signed by "Grand Media, TOV". Once installed it registers torrent and magnet-link associations and offers to become your default torrent client. The redirect chain carries affiliate tracking, which points at a straightforward commercial motive: somebody gets paid per install.
Here is the part that deserves saying plainly, because Malwarebytes said it plainly: "our analysis did not establish that Download Studio itself is malware. What this campaign clearly demonstrates is that people looking for one piece of software are being deceptively funneled into installing another."
So this isn't a story about a virus. It's a story about consent. You went looking for VLC. You watched a link that said VLC. You ended up somewhere that installs something else. The deception happened in the two hundred milliseconds between your hover and your click.
The visible name lies in other ways too
Eight days earlier, the same researcher documented a different campaign with a different trick, and it's worth knowing because it fails in a similar place: the name you can see.
Those were lookalike sites impersonating CNN, Avast and Stremio, at app.cnn-news[.]net, avast-premium[.]shop and stremiotv[.]online. They served downloads named CNN_App.setup….exe, AVAST_App.setup….exe and Stremio_App.setup….exe. The files were actually O&O Syspectr, a legitimate remote-administration tool, carrying account IDs belonging to the attackers, which is how a legitimate tool becomes somebody else's way into your PC.
There's no hover-versus-click mismatch in that one. The useful lesson is narrower and still worth having: a filename can be typed by anyone. On Windows, right-click the downloaded file, open Properties, and look at the digital signature and product name. That tells you what the file really is, regardless of what it's called.
So what do you actually check?
The address bar, after you land. It's less satisfying than a check you can do before clicking, but it's the one address that is definitely real, because your browser is reporting where it genuinely is rather than where a page said it would go.
- Click if you must, then stop. Landing on a page is not the dangerous part. Typing a password into it, or running a file from it, is.
- Read the address bar right to left. Find the first single slash after the site name, then the last dot before it. The two words in front of that slash are the site you are truly on: in
vlc-download.something.co/free, the real site issomething.co, not VLC. - Compare it to where you meant to be. If you were going to VideoLAN, the address should end in
videolan.org. Anything else is a stranger, however good the page looks. - Check the domain you landed on before you download or sign in. Its age, whether it's a lookalike of the brand, whether Google Safe Browsing has flagged it.
- Prefer arriving on purpose. Type the official address yourself, or use a bookmark. A link you didn't choose is a link somebody else chose for you.
Malwarebytes' own advice to readers is the same, and worth quoting exactly: "Don't rely on hovering over a link alone. As this campaign shows, a page can display a legitimate destination and then send you somewhere else when you click."
Where IP Tracker fits
IP Tracker is a free Chrome extension. It doesn't sit between you and your clicks; it's the second opinion you get on the address you ended up at. Open it on the page you landed on, or paste a domain, a link or a full email address into the popup. The free tier is 50 checks a day, with no account and no tracking, and only the value you paste is looked up.
On the download-page problem specifically, it will tell you whether the domain you're standing on is a lookalike of a brand it knows (roughly 125 widely impersonated brands, checked with letter-swap normalisation and a typo-tolerant comparison), whether Google Safe Browsing has flagged it, how many security vendors flag it on VirusTotal, whether there are community abuse reports against the address behind it, and how old the domain is. A site registered eleven days ago that mimics a twenty-year-old software project is a fact worth having before you run its installer.
It also shows the addresses the domain resolves to and the hosting platform behind it, and it is careful about what that means: a shared CDN address is used by thousands of unrelated sites, so it never counts as evidence against any of them.
What can't it do?
Four limits, stated straight:
- It can't see a page's JavaScript. The hover-versus-click mismatch happens inside the page's own code. IP Tracker checks domains, not scripts. It can only help once you know which domain you're on.
- It can't inspect the file you downloaded. Nothing in a domain check tells you what's inside
DS-Setup.exe. That's a job for your antivirus, plus the Properties-and-signature check above. - A valid signature is not an endorsement. The installer in this campaign was properly signed. A signature says who published a file, not whether you wanted it.
- Blocklists lag. Google Safe Browsing is strong on known bad sites, but a brand-new deceptive download page can go unlisted for a while, and the sites in this campaign were not, in Malwarebytes' analysis, established as malware at all.
The old rule wasn't wrong, it was just built on an assumption that no longer holds: that a page which shows you an address has to honour it. It doesn't. Move your check to the other side of the click, where the address is a fact instead of a claim.
To summarize:
- ✓ Treat the hover preview as a claim, not proof.
- ✓ Read the address bar after you land, right to left.
- ✓ Check the domain before you download or sign in, not after.
- ✓ On Windows, check a downloaded file's Properties for its real signed product name.
- ✓ When you can, arrive on purpose: bookmark or type the official address.
Trust the address you land on, not the one you were shown. 😎
Sources
- 41 deceptive download sites show a real link, then send you somewhere else, Stefan Dasic, Malwarebytes Labs, August 19, 2026.
- Fake popular sites offer a free app, instead take over PCs, Stefan Dasic, Malwarebytes Labs, August 11, 2026.