Is aimmy.dev legit or a scam?
Aimmy.dev offers an AI-powered game cheat tool that has recently been flagged for distributing malware and causing permanent hardware bans in popular games.
These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.
Analysis Summary
Warning signs detected
Aimmy.dev offers an AI-powered game cheat tool that has recently been flagged for distributing malware and causing permanent hardware bans in popular games. Several risk indicators suggest caution. This site might be legitimate — but treat it as unverified until you can independently confirm.
Website Preview

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site. See full visual analysis →
Visual Screenshot Analysis
We capture a fresh screenshot of the live page and ask a vision model to look for scam visual patterns — fake trust badges, countdown timers, overlay pop-ups, and visual clones of legitimate brands.
Visual red flags detected in the screenshot
The page appears to be a legitimate landing page for a software project called Aimmy, featuring links to its source code and community. While the software's nature as an 'aiming' tool may be controversial in gaming contexts, the site itself does not exhibit typical visual scam patterns.
What our vision model saw
5 signalsProminent download buttons for Windows software
Links to external platforms including GitHub and Discord
Claims of 'AI-Based Aiming Nomenclature' which may relate to game automation or cheats
Professional layout with consistent branding and navigation
No immediate signs of phishing, fake urgency, or cloned branding
Brand Impersonation
medium confidenceThe page mentions or styles itself as Fortnite, but is hosted on a domain that is not an official Fortnite property.
MT Intelligence
The site serves as the landing page for 'Aimmy,' an AI-driven aiming tool. While the project has a significant following on GitHub, our research indicates that downloads from this specific domain have been flagged by sandbox analysis for malicious activity, including registry changes and unauthorized binary execution. There are also documented reports of 'supply-chain' attacks where malicious clones of this project distribute trojans. Furthermore, the software's nature as a game cheat leads to high risks of permanent hardware ID (HWID) bans on platforms like Fortnite. Because the site lacks formal business registration and distributes executable files that trigger multiple security warnings, it carries a high risk for average users.
Web Research Findings
Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for aimmy.dev, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.
- Official site for open-source-available AI aim alignment tool (YOLOv8 + ONNX + DirectML) hosted at GitHub.com/Babyhamsta/Aimmy with 1.5k stars; marketed for accessibility but widely used as external aimbot/cheat for Roblox, Fortnite, etc.
- Site explicitly warns it causes HWID bans in Fortnite and is unsuitable for Valorant, Apex, Warzone, EAC, or BattlEye; developers state they are not responsible for bans.
- ANY.RUN sandbox flagged a download from aimmy.dev (Feb 2026) as malicious with MENORAH YARA rule, registry autorun changes, and renamed binary (YmmiaV2.exe); likely indicates tampered/malicious build or fake mirror.
- Multiple GitHub issues and discussions report VirusTotal detections, trojans (Backdoor.MSIL), and AV false positives due to mouse control/screen capture behavior; users advised to download only from official GitHub releases.
- Scamadviser rates it "Very Likely Safe" / legit with valid SSL but notes low Tranco rank; Trustpilot shows 3.2/5 from only 2 reviews.
- Domain age ~904 days (~2.5 years); project described as non-commercial passion project with low operating costs, source-available but not fully open-source (prohibits commercial forks and malware-modified distributions).
- Fake/malicious clones (e.g. aimmy.app) have been used in supply-chain attacks targeting Aimmy users via modified downloads.
- ANY.RUNopen
"Malware analysis aimmy.dev Malicious activity... Verdict: Malicious activity... Tags: github menorah auto generic... MENORAH has been detected (YARA) * YmmiaV2.exe"
- GitHub Discussionopen
"Just found this trojan as part of a file for Aimmy an AI cheat... This is a Backdoor.MSIL.gkhl a malicious tool"
- OpenAnalysis Researchopen
"The malware operators have made a clone of the GitHub repository... and setup a malicious website https://aimmy.app which links to the cloned GitHub repository. The website also has a modified download link which links to malware"
- Scamadviseropen
"In summary, we think aimmy.dev is legit and safe for consumers to access."
- Trustpilotopen
"aimmy.dev ... 3.2 Average. TrustScore 3 out of 5. 2 reviews."
- GitHubopen
"Aimmy is a universal AI-Based Aim Alignment Mechanism developed by BabyHamsta, MarsQQ & Taylor to make gaming more accessible for users who have difficulty aiming... 1.5k stars, 672 forks"
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Contact Verification
We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.
- No phone number listed on the page.
- No postal address visible on the page.
- Page impersonates Fortnite on a non-official domain.
- Contact email on the site's own domain (info@aimmy.dev).
Domain & Encryption
Server Reputation
Proceed with caution
Our automated review flagged enough risk that you should treat this site as unverified.
- Treat aimmy.dev as unverified
Do not enter credentials or send money until you have independently verified the business.
- Verify the business through independent channels
Check the company's social profiles, registry records, and search for recent news or reviews that are not hosted on the site itself.
- Never use irreversible payment methods
Crypto, gift cards, wire transfers, and cash apps offer zero buyer protection. Use a credit card or PayPal if you must pay.
- OpenShare your experience
If you have additional context, drop a comment below or post on the MalwareTips forum.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
Safety FAQ
Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.
- Our automated security review marked aimmy.dev as suspicious. Several warning signs were detected; it may still turn out legitimate, but you should verify it through independent channels before trusting it with money or credentials.
- aimmy.dev currently scores 49/100 on our trust scale. We found enough warning signals to recommend caution. Verify the site through independent channels before entering credentials or money.
- Yes. aimmy.dev presents a valid TLSv1.3 certificate issued by Let's Encrypt · R12, expiring in 32 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
- aimmy.dev is 2.5 years old, registered on 1/5/2024 through Namecheap Inc.. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
- No. All 92 antivirus engines in our malware network report aimmy.dev as clean.
- No. aimmy.dev is not currently listed on the major browser blocklist feeds that modern browsers use.
- aimmy.dev resolves to an IP operated by GitHub, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
- This is a permanent record of the scan run on June 27, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around aimmy.dev have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.