The download link says Steam. Your click goes somewhere else.
Hover over a link and your browser shows the destination in the bottom corner of the window. That small grey line of text is one of the few honest signals left on a web page. Forty-one websites have worked out how to lie with it.
Malwarebytes published the findings on Wednesday. The sites impersonate things people genuinely search for - Counter-Strike, GTA VI, Fallout, Roblox, PUBG - and, from the duller shelf, VLC, 7-Zip, Paint.NET, Avast, Acronis and Recuva. Real screenshots, real product blurb, and a download button whose underlying link points at the actual Steam store page. Hover it, Steam is what you see. Click it and JavaScript on the page catches the click and sends you through an affiliate redirect instead. In Malwarebytes' phrasing: the link you see isn't the link you follow.
What lands is a 73 MB installer for Download Studio, validly signed by a firm called Grand Media, TOV. Windows inspects that signature and finds nothing wrong, because nothing is wrong with it. A signature tells you who signed a file; it says nothing about whether that file is the one you went looking for. Download Studio grabs your torrent and magnet links and installs its own auto-updater, and that updater has history - in 2020 Avast caught it quietly pushing FakeMBAM, a backdoor dressed as a Malwarebytes installer, which ran cryptocurrency miners on the PCs it reached.
The habit that defeats all of this is free: type the maker's address yourself instead of clicking the top search result. If something has already downloaded, right-click it, pick Properties and read the Details tab - the program's real name is in there, and it's often not the name on the page you came from. Tendvane's Safety check is for the aftermath, flagging software that installed itself without a clear invitation, and its app updates come through winget rather than whatever download page a search engine served up.