Open-Source/Freeware Impersonation + Click-Hijacking TDS Ecosystem Delivering RemusStealer, AnimateClipper & SessionGate
Open-Source/Freeware Impersonation + Click-Hijacking TDS (TL-2026-0678), also tracked as Ghidra/dnSpy/SpiderFoot fake download campaign, is a high-severity malware campaign, first published 2026-06-04. It has no confirmed attribution, affects N/A Windows endpoints (search users of open-source/security tooling), maps to 27 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 47 indicators of compromise.
Key facts for TL-2026-0678
- Threat ID
- TL-2026-0678
- Also known as
- Ghidra/dnSpy/SpiderFoot fake download campaign, Gated TDS malware distribution ecosystem
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-04
- Last reviewed
- 2026-06-04
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, security-research, cryptocurrency, finance, consumer
- Target regions
- Europe, South America, Middle East, North America, Global
- Detection rules
- 9
- Indicators of compromise
- 47
Malware and tooling in Open-Source/Freeware Impersonation + Click-Hijacking TDS
Malware and tooling: AnimateClipper, RemusStealer, SessionGate, Gated Traffic Distribution System (TDS)
Check Point Research exposed a large-scale distribution ecosystem of 100+ websites impersonating open-source and security tooling (Ghidra, dnSpy, ILSpy, SpiderFoot lookalikes) that load CloudFront-hosted JavaScript to hijack the first 'download' click and hand the visitor to a gated Traffic Distribution System (TDS). The gated TDS enforces first-visit state, mandatory-click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering and localStorage frequency capping before selectively routing real users to malicious payloads: the RemusStealer infostealer, the AnimateClipper multi-chain crypto clipper, the multi-stage SessionGate loader, and PUA/offer-wall monetization.
How Open-Source/Freeware Impersonation + Click-Hijacking TDS works
Check Point Research (CPR) documented a malware distribution ecosystem that monetizes search traffic for open-source and freeware tooling while serving as a delivery channel for multiple malware families. Operators registered 100+ lookalike domains impersonating developer and security tools (ghidralite.com, dnspy.org, ilspy.org, grpcurl.com, mqttexplorer.com, mfcmapi.com, winsetupfromusb.org, crystaldiskmark.org, guiformat.com) to capture organic search traffic. Each page loads a CloudFront-hosted JavaScript staging layer that intercepts the first eligible user interaction (click/mousedown), calls preventDefault() and stopImmediatePropagation(), and converts a click on the 'download' button into a handoff to a gated Traffic Distribution System (TDS).
The browser-side TDS enforces strict gating: first-visit state checks, mandatory click confirmation, anti-bot and anti-analysis logic, VPN/datacenter filtering, per-client session binding, and localStorage-based frequency capping (capPerDomain, capPerUri, intervalBetweenPops_ms, resetInterval_sec). A decoded config exposed tagId 1230479, redirectorDomain oundhertobeconsist.org and pixelDomain ukentaspectsofc.org. Eligible visitors are routed through a redirector chain (oundhertobeconsist.org/{token}) to offer walls (unlockcontent.org), multi-gate/anti-bot services (trkscope.xyz, file-enter-web.com) and archive delivery hosts (media.stellarcloudhub1.cfd, arch2.maxdatahost1.cyou, mega.nz).
SessionGate is a multi-stage loader engineered to make recovery of the final payload extremely difficult. Stage 1 (NSIS/7-Zip SFX downloader, User-Agent 'NSIS_InetLoad') performs Adler-32/SHA1 hash-table environment checks for EDR/AV drivers (eelam, ehdrv, eamonm, epfwwfp, epfw, ekbdflt, edevmon, npf, npcap, sysmondrv) and Windows Defender registry keys (PUAProtection, MpEnablePus), then beacons to C2 (appfreshstart.com, appgetonline.com, webinnosetup.com, appmakingcenter.com) with a SHA1-based signature scheme. Per-session S3 buckets (s3.us-east-2.amazonaws.com) generate one-time payload URLs (Download_Ready_{id}.exe). Stage 2 embeds an obfuscated ~5MB loader plus ~15MB archive using opaque predicates, junk code and post-branch string encryption, chaining two DLLs with SHA256-derived keys; DLL #1 is an AES-256-CBC key broker (key BFEA4EE8EF934BE7A2B4C64A0BAD1E92, zero IV) contacting CRC C2 domains (yourfastcrc.com, mobileversioncrc.com, webcrcprove.com, integritycrc.com), and DLL #2 is an installer/offer framework pushing PUAs (PDF Spark, PDF Proton, PDF Ignite, NibblrAI, PCPooch).
RemusStealer is a newly emerged infostealer (first underground listing 2026-02-12) delivered as a password-protected ZIP (~14MB) that extracts to an ~850MB zero-padded executable to defeat sandboxes and size-limited scanners. A Go first-stage performs manual PE mapping. It steals from 20+ Chromium and Firefox/NSS browsers and tasks against 332 targeted extensions/applications including 220 crypto wallets (MetaMask, Phantom, Trust Wallet, OKX, Keplr, TronLink, Exodus), 77 password managers (1Password, Bitwarden, LastPass, KeePassXC) and 18 2FA/TOTP tools (Authy, 2FAS). It performs DPAPI key extraction from Local State, clipboard theft (Clipboard.txt), screenshots (Screenshot.bmp), file-system and registry reconnaissance, and exfiltrates over HTTP POST with an access_token UUID and step counter to C2 such as buccstanor.pics:28313, baxe.pics:48261, 217.156.122.75:1378 and 94.231.205.229:28313.
AnimateClipper is a cryptocurrency clipboard hijacker covering 20+ blockchain ecosystems. It is delivered via a ClickFix lure (processing-in-progress-x4.t3.storage.dev) executing mshta.exe against a hex-IP-obfuscated HTA (185.0xA1.0xFB.58/navy.7z), then staged through obfuscated PowerShell (194.150.220.218), a Python/Node.js ZIP, and a node_modules.asar Python loader that runs embedded shellcode in-process via ntdll!LdrCallEnclave and reflectively maps the final PE. It resolves C2 from an on-chain contract (0x6936edc505501EBB2F202C985a021a06f1c10C9E) on BNB Smart Chain Testnet RPC, yielding C2 such as kr.hugo-lapp.co and *.hugo-lapp.lat, and monitors the clipboard to swap victim wallet addresses for attacker-controlled BTC/LTC/XMR/ETH/TRX/XRP/Cosmos/TON addresses. Earliest attacker wallet inbound payment was observed 2025-07-12.
Although the ecosystem is primarily a gray-monetization operation, the same gated TDS that drives ad/PUA revenue selectively routes genuine users to these stealer and clipper payloads, making operators a turnkey distribution channel for downstream malware. CPR telemetry shows 5,000+ related VirusTotal submissions with victims across Turkey, Poland, Brazil, Germany, France, Russia and the UK.
MITRE ATT&CK techniques used in TL-2026-0678
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data
Discovery
T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Initial Access
execution
stealth
T1218 System Binary Proxy Execution
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Impact
defense-impairment
Affected products and versions in Open-Source/Freeware Impersonation + Click-Hijacking TDS
- N/A — Windows endpoints (search users of open-source/security tooling)
Vulnerable versions: Windows 10; Windows 11; Windows Server - N/A — Chromium-based browsers (Chrome, Edge, Brave, etc.)
Vulnerable versions: 20+ browser families - Mozilla — Firefox / NSS profiles
Vulnerable versions: all - N/A — Browser crypto-wallet / password-manager / 2FA extensions
Vulnerable versions: 332 targeted extensions/apps
Remediation for Open-Source/Freeware Impersonation + Click-Hijacking TDS
Immediate actions
- Block the documented impersonation, redirector, CloudFront staging, S3 payload, and C2 domains/IPs at web proxy, DNS and perimeter.
- Hunt for NSIS_InetLoad User-Agent and Download_Ready_*.exe downloads from s3.us-east-2.amazonaws.com.
- Alert on mshta.exe spawning from browsers or fetching hex-encoded IP URLs (e.g. 185.0xA1.0xFB.58).
Workarounds
- Restrict execution of HTA/mshta.exe and unsigned NSIS installers via WDAC/AppLocker.
- Block outbound traffic to newly registered low-reputation TLDs (.pics, .lat, .cfd, .cyou, .digital) where business need is absent.
Longer-term hardening
- Deploy EDR with behavioral detection for reflective PE loading, LdrCallEnclave shellcode execution, and clipboard-hijack patterns.
- Enforce download allow-listing and obtain developer/security tools only from official vendor or distribution channels.
- Monitor clipboard-replacement of cryptocurrency addresses and deploy address-integrity checks in finance/treasury workflows.
Weaknesses (CWE) in Open-Source/Freeware Impersonation + Click-Hijacking TDS
CWE-494, CWE-829, CWE-451
Timeline of Open-Source/Freeware Impersonation + Click-Hijacking TDS
- Earliest observed inbound payment to an AnimateClipper attacker-controlled cryptocurrency wallet.
- Earliest VirusTotal submissions of SessionGate Stage 2 loader samples.
- FullStory reports the fraudulent impersonation domain cluster; no direct malware abuse identified at that time.
- Gated TDS scripts embedded into the impersonation-site workflow.
- Active malware distribution via the TDS infrastructure observed from early January 2026 onward.
- RemusStealer first appears for sale on an underground forum.
- Check Point Research publishes the full analysis of the impersonation/click-hijacking/TDS ecosystem.
- Threadlinqs Intelligence ingests and analyzes the campaign for detection coverage and IOC publication.
Sources cited for Open-Source/Freeware Impersonation + Click-Hijacking TDS
- Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
- Check Point Research Exposes Hidden Malware Pipeline Behind Fake Open-Source Download Sites
- Huge hacking campaign uses spoofed Ghidra, dnSpy, and SpiderFoot security tools
- Check Point Research (CPR) — Threat Intelligence Hub
- MITRE ATT&CK — Reflective Code Loading (T1620)
Threats related to Open-Source/Freeware Impersonation + Click-Hijacking TDS
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and Application-Bound Encryption Bypass
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading
- Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes
Detection coverage for TL-2026-0678
As of 2026-06-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0678 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.