41 fake download sites show you Steam, then install malware—and hovering over the link won’t save you

11 Min Read

You hover your mouse over a download link for Steam, Blender, or OBS Studio—the safety check you’ve relied on for years—and the address bar shows exactly what you expect. Then you click, and malware begins installing.

Security researchers at Malwarebytes have identified 41 deceptive download sites using a technique that defeats one of the most basic user defenses: the link preview. The sites display legitimate URLs when you hover over them, creating the illusion of safety, but redirect users to malware installers the moment they click. It’s a precision attack on the assumption that checking before you click will protect you.

Key Findings:
  • The Hover Deception: 41 identified sites display legitimate URLs on hover but silently redirect to malware installers the instant a user clicks, defeating the most common visual verification habit.
  • High-Trust Targets: The campaign specifically impersonates widely used tools—Steam, Blender, and OBS Studio—chosen because their users are ordinary people, not security professionals.
  • The Signature Gap: Malware installers distributed through these sites lack valid digital signatures, meaning users who perform that specific check would catch the fraud—but most never do.

The scale is modest but the implication is unsettling. Forty-one sites may sound small until you consider that each one can be shared across forums, social media, and search results, reaching thousands of people searching for popular, legitimate software. The sites target widely used tools: Steam (the gaming platform), Blender (3D creation software), OBS Studio (streaming software), and others. People downloading these tools are not security experts. They’re ordinary users trying to install software they trust.

The technique works because it exploits a gap between what users see and what actually happens. When you hover over a hyperlink in your browser, the address bar or status bar displays the URL—a practice so ingrained that most people treat it as a verification step. “Is this the real Steam download?” you ask yourself, see the legitimate domain in the preview, and proceed. The attacker’s site, however, uses JavaScript or other client-side code to swap the destination URL only after the click registers. By then, your browser is already navigating away.

Why Does the Hover-Preview Attack Work So Reliably?

Malwarebytes did not name the specific malware families being distributed through these 41 sites, nor did the company disclose how many users may have been affected. The research team confirmed that legitimate digital signatures—the cryptographic markers that verify software authenticity—were not present on the malware installers, meaning users who checked for those signatures would have caught the fraud. But most users don’t perform that check.

This attack pattern mirrors a structural problem that has defined some of the most consequential digital deceptions of the past decade: the weaponization of trust signals. The Cambridge Analytica scandal exposed how behavioral data could be harvested at scale by exploiting users’ trust in familiar platforms and interfaces. The firm’s micro-targeting operation relied on the assumption that users would not question the source or authenticity of the content they encountered. Here, the attacker is doing something structurally analogous—hijacking the visual trust signal (the link preview) to manufacture a false sense of legitimacy. The malware distributor is not stealing your psychographic profile; they’re stealing your assumption that you’ve already verified the source. Both rely on the user’s dependence on a single, easily spoofed signal of authenticity.

What Research Shows:
A large-scale classification study of VirusTotal reports on phishing and malware URLs found that malicious download infrastructure consistently mimics the visual and structural patterns of legitimate software distribution networks, making automated and human detection significantly harder.
Research on detecting fraudulent URLs using machine-learning techniques demonstrates that deceptive URLs frequently pass basic visual inspection precisely because attackers engineer them to resemble trusted domains at a glance.
A systematic review of user deception techniques in digital environments documents that social engineering attacks succeed most often when they target habitual, low-effort verification behaviors—exactly the kind of hover-check most users rely on.

The sites themselves appear professionally constructed. They use domain names similar to official sources, include screenshots and descriptions that match the legitimate software, and display download buttons prominently. A user arriving from a search result or a shared link might spend only seconds on the page before clicking. The hover-preview trick is designed to collapse that already-brief window of scrutiny into near-zero.

How Are These Malicious Sites Reaching Ordinary Users?

Malwarebytes’ researchers emphasized that “a legitimate-looking link or valid digital signature can offer false reassurance,” but the inverse is also true: the absence of a verification method you can actually see—like a digital signature check—leaves you vulnerable to this kind of deception. Most users have no practical way to verify a digital signature before downloading. They rely instead on visual cues: the domain name, the page design, the link preview. This is precisely the kind of behavioral data weaponization that security researchers have warned about for years—not the theft of data in transit, but the exploitation of the mental shortcuts users have been conditioned to trust.

Your exposure depends on where you search. If you use Google, Bing, or another search engine to find download links, you may encounter these sites in results, especially if the legitimate site’s SEO is weak or if the attacker’s site is well-optimized. If you click links shared in forums, Discord servers, or social media without verifying the domain yourself, the risk is higher. The sites are not being promoted through ads or official channels—they’re fishing for users who make a small mistake in their search or trust a recommendation from someone who was already compromised.

By the Numbers:
• 41 deceptive download sites identified in this specific Malwarebytes research sweep, each capable of reaching thousands of users through search results and shared links
• Zero valid digital signatures present on the malware installers distributed through these sites—a detectable red flag that most users are not equipped to check
• Three major software platforms impersonated—Steam, Blender, and OBS Studio—chosen for their large, non-specialist user bases and high search volume

What Happens After the Malware Installs?

What happens after the malware installs depends on the payload. Malwarebytes did not specify whether these particular installers deliver ransomware, spyware, cryptominers, or credential-stealing trojans. Different malware families have different objectives. Some steal banking information. Others lock your files and demand payment. Some run silently in the background, harvesting data or using your computer’s processing power. The ambiguity itself is part of what makes this category of attack so difficult to assess—the user may not know they are infected until significant damage has already occurred.

The company has not disclosed whether it has notified the operators of the legitimate software projects (Valve for Steam, the Blender Foundation, etc.) or whether those companies have issued warnings. It’s also unclear whether the 41 sites remain active or have been taken down. The broader pattern of deceptive download infrastructure is not new, but as experts have repeatedly warned, the sophistication of social engineering attacks continues to advance in direct proportion to users’ growing awareness of older, cruder methods.

For you, the practical lesson is uncomfortable: hovering over a link is not a reliable safety check anymore. It may never have been, but this attack makes that vulnerability explicit. Before downloading software, verify the domain name carefully—not just a glance, but a deliberate check against the official source. Visit the official website directly rather than clicking a link from search results. If you must use a link, type the domain into your address bar yourself. Look for HTTPS and a valid SSL certificate, though those are increasingly common on malicious sites too.

If you’ve downloaded software in the past few weeks from unfamiliar sites, consider running a full system scan with reputable antivirus software. Check your installed programs list for unfamiliar applications. If you notice unusual network activity, unexpected CPU usage, or slow performance, those may be signs of infection.

The 41 sites represent a small but growing category of attacks that exploit the gap between user expectations and technical reality. As security measures improve, attackers refine their social engineering. The hover-preview trick works because it targets the one verification step most users actually perform. Understanding how trust exploitation has evolved across digital platforms is essential context for anyone trying to understand why these attacks keep working. It’s a reminder that no single safety check is foolproof, and that the most dangerous vulnerabilities are often the ones we’ve learned to trust.

Share This Article
Miora Danielle Raveloarison is a journalist at CA Privacy Watch covering surveillance, data privacy and the human impact of technology. A graduate of the Catholic University of Madagascar with a background in the social sciences, she has spent over a decade turning complex subjects into clear, engaging reporting, and brings a humanistic lens to questions of privacy, AI and digital rights.