Hackers have created a fake Microsoft DirectX 12 download page to distribute malware that steals your wallets and passwords.

Although the website comes with a contact form, a privacy policy, a disclaimer, and a DMCA violation page, there is nothing legal about the website or the programs it distributes.

See also: Prometei botnet targets unpatched Microsoft Exchange servers!
After users click the Download buttons, they are taken to an external page that asks them to download a file. Depending on whether you click on the 32-bit or 64-bit version, you will be offered a file named '6080b4_DirectX-12-Down.zip' [VirusTotal] or '6083040a__Disclaimer.zip' [VirusTotal].
What both of these files have in common is that they lead to malware that attempts to steal files, passwords, and cryptocurrency wallets. The malware was first discovered by security researcher Oliver Hough.
See also: Office 2021/Office LTSC: Microsoft releases first previews
This malware is an information-stealing malicious software that attempts to collect the victim's cookies, files, information, installed programs, and even a screenshot of the current desktop.

With the cryptocurrency craze in full swing, malware developers are also trying to hijack a wide variety of cryptocurrency wallets for Windows software, including Ledger Live, Waves.Exchange, Coinomi, Electrum, Electron Cash, BTCP Electrum, Jaxx, Exodus, MultiBit HD, Aomtic, and Monero.

All data is collected in a %Temp% folder, which the malware will zip and send back to the attacker. The attack can then analyze the data and use it for other malicious activities.
Hackers are increasingly creating fake websites, and in many cases, much more convincing ones, to distribute malware.
See also: Microsoft just fixed the Windows 10 bug that causes issues with games
As DirectX is a Microsoft feature, it makes sense to only download it from the Microsoft site and that downloading it from anywhere else could lead to problems.
Information source: bleepingcomputer.com
