← Blog
For individuals

A Site That Looks Just Like CNN Wants You to Download One File. Don't.

Explore an AI summary

Key takeaways

  • Fake websites impersonating CNN, Avast, and Stremio (plus a fake crypto-mining game) offer a "free app" that is really a remote-access tool in disguise.

  • What you install is O&O Syspectr, a real, digitally signed IT tool. In an attacker's hands it gives them remote control of your PC: files, commands, and installing more software.

  • Because the file is legitimate signed software, not malware, antivirus has little reason to flag it. The signature looks clean.

  • The only reliable defense is at the page and the download: don't trust a lookalike site, and know what a file is before it runs.

  • Haven helps in two ways here. It flags the fake site for you, and on unverified sites it pauses downloads so you can see what is about to land on your device before it does.


You search for an app you actually want, land on a page that looks exactly like CNN, Avast, or a media app you recognize, and click the big "free download" button. Nothing looks wrong. But the file you just ran is not the app on the page. It is a real, legitimate remote-control program, quietly linked to a stranger's account, and now that stranger can operate your computer as if they were sitting at it.

The unsettling part: this is not a virus, so your antivirus has little reason to stop it. Security researchers at Malwarebytes uncovered this fake app download scam running across several fake brand sites at once. Here is exactly how it works, why your usual protection misses it, and the two things that actually catch it in time.


What the fake pages look like

The centerpiece of the campaign is a fake CNN homepage. It copies the real thing closely: current headlines, the familiar layout, even a red "Live Updates" tag on a real story. Moments after you arrive, a pop-up appears: "Get the latest news first in the new CNN app, it's live and free," with a red Download button. There is no real CNN app behind it.

The same trick runs under other trusted names. One lookalike site copies Avast's download page, logo, review scores, and a blue "Free download" button for "Avast One." Another copies Stremio, a legitimate media-center app. And where there is no famous brand to borrow, the attackers invent a hook instead: a fake "idle miner" browser game showing a ticking crypto balance and a "Download Miner Plugin" button promising faster payouts.

Different faces, one goal: get you to download and run their file.


What you actually install

Behind every one of those buttons is the same thing: an installer for O&O Syspectr, a genuine remote-administration tool made by a real German software company and sold openly to IT departments.

Used legitimately, it lets an IT admin manage a computer from afar. Used against you, the paid features are the problem. Whoever set up the account can remotely control your computer, browse your files, run commands, install more software, and change system settings as though they were sitting in front of it. Malwarebytes confirmed the CNN, Avast, and Stremio downloads all trace back to a single attacker's Syspectr account, simply reskinned with different branding. The fake crypto game pointed to a second account running the same playbook.

So the "free app" does not steal your password on the spot. It quietly opens a door and lets a stranger walk in whenever they like.


Why your antivirus won't stop it

Here is the twist that makes this scam so effective. The file is not malware. It is a real, digitally signed program from a legitimate company.

Antivirus is built to catch malicious software. It is not built to block a legitimate, properly signed business tool just because of how it arrived on your computer. The signature checks out, so nothing trips the alarm. The attacker never has to sneak past your antivirus at all. They only have to convince you to install a real tool that is already tied to their account.

That is why the usual advice ("just run antivirus") does not cover this one. By the time the tool is installed, it looks like software you chose to install. The place to stop it is earlier: before you trust the page, and before the file lands on your machine.


The two things Haven does here

This is exactly the kind of scam Haven is built for, and it helps at the two moments that matter.

First, Haven flags the fake site for you. It analyzes the actual page in front of you, not just how it looks or how you got there, so when a page imitates CNN, Avast, or another brand on a lookalike domain, Haven warns you that it is not the real, verified site, before you click download.

Second, on unverified sites, Haven pauses downloads so you know what is about to land on your device. Instead of a file quietly saving and running, you get a moment to see what it actually is and decide, rather than discovering later that "CNN_App.exe" was a remote-control tool. That pause is the difference between catching this and cleaning up after it.

Together, those two steps cover the exact gap antivirus leaves open here: the file itself looks legitimate, so the real protection is not trusting the fake page and not letting an unexpected download run unchecked. If you want to check a link before you visit, you can also paste it into Haven's free link checker.

To be clear about scope: Haven works in your browser, at the page and the download. It flags fake and unverified sites and pauses downloads there so you can decide. It is not antivirus, and it does not scan the contents of a file, verify a digital signature, or remove software that is already installed. Its job is to stop you from reaching that point, by catching the fake page and giving you a beat before anything lands.


How to protect yourself

A few habits shut this down:

  • Get apps from the vendor's real website or an official app store, not from a search result or ad. Type the address yourself.

  • Be suspicious of any pop-up urging you to download a "new app" the moment you land on a page, even a page that looks legitimate.

  • If you are unsure about a Windows installer before running it, right-click it, choose Properties, and open the Details tab. The "File description" and "Product name" fields reveal what the file really is. In this campaign, every file identified itself as O&O Syspectr, no matter what the download button claimed.

  • If you find O&O Syspectr installed and did not set it up yourself, remove it through Settings, Apps, and run a full antivirus scan.

  • If you already ran one of these installers, change passwords for anything sensitive from a different, clean device, and get help from a trusted IT professional.

The face on the page keeps changing, CNN one day, an antivirus brand the next. The move underneath stays the same: impersonate something you trust, offer a free download, and get you to run it. Slow down at the page and the download, and it falls apart.


About Haven

Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link, enter your password, or download a file, flagging fake and impersonated login pages, suspicious links, and lookalike sites, and pausing downloads on unverified sites so you can see what is about to land on your device. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.

Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

Frequently asked questions

Is the "new CNN app" download real?
No. There is no "new CNN app" behind these pop-ups. Security researchers found fake sites copying CNN's homepage to push a "free app" that is actually a remote-access tool called O&O Syspectr, which lets a stranger control your PC. Get news apps only from CNN's official site or an official app store, never from a pop-up on a page you reached through search.
Can a downloaded app give someone remote control of my computer?
Yes. In this scam, the downloaded file installs O&O Syspectr, a legitimate remote-administration tool. Once it is installed and linked to an attacker's account, they can remotely view your files, run commands, install more software, and control the machine as if they were sitting at it. That is why it is risky to run any installer you got from a lookalike site or pop-up rather than the real vendor.
Why didn't my antivirus stop the fake app download?
Because the file is not malware. It is a real, digitally signed program from a legitimate company, so antivirus has little reason to block it. Antivirus detects malicious software; it does not flag a properly signed business tool just because of how it reached your computer. The reliable defense is to avoid the fake page and know what an installer is before you run it.
How can I tell what an installer really is before I run it?
On Windows, right-click the installer, choose Properties, and open the Details tab. Look at the "File description" and "Product name" fields, which come from the signed software itself and cannot be changed without breaking the signature. In this campaign, those fields identified every file as O&O Syspectr, even when the download button claimed it was a CNN, Avast, or Stremio app.
What are the two things Haven does to stop this scam?
Haven does two things at the moments that matter. First, it flags the fake or unverified site for you, warning that a page imitating CNN, Avast, or another brand is not the real one before you click download. Second, on unverified sites it pauses downloads so you can see what is about to land on your device and decide, instead of a disguised file saving and running unnoticed. Haven works in the browser and is not antivirus, so it does not scan files or remove installed software.
Is Haven free?
Yes. Haven is free for individual use. Haven for Business extends browser-level protection to teams. Haven is operated by MirrorTab, Inc.