Open-Source/Freeware Impersonation + Click-Hijacking TDS Ecosystem Delivering RemusStealer, AnimateClipper & SessionGate

Open-Source/Freeware Impersonation + Click-Hijacking TDS (TL-2026-0678), also tracked as Ghidra/dnSpy/SpiderFoot fake download campaign, is a high-severity malware campaign, first published 2026-06-04. It has no confirmed attribution, affects N/A Windows endpoints (search users of open-source/security tooling), maps to 27 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 47 indicators of compromise.

Key facts for TL-2026-0678

Threat ID
TL-2026-0678
Also known as
Ghidra/dnSpy/SpiderFoot fake download campaign, Gated TDS malware distribution ecosystem
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-04
Last reviewed
2026-06-04
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, security-research, cryptocurrency, finance, consumer
Target regions
Europe, South America, Middle East, North America, Global
Detection rules
9
Indicators of compromise
47

Malware and tooling in Open-Source/Freeware Impersonation + Click-Hijacking TDS

Malware and tooling: AnimateClipper, RemusStealer, SessionGate, Gated Traffic Distribution System (TDS)

Check Point Research exposed a large-scale distribution ecosystem of 100+ websites impersonating open-source and security tooling (Ghidra, dnSpy, ILSpy, SpiderFoot lookalikes) that load CloudFront-hosted JavaScript to hijack the first 'download' click and hand the visitor to a gated Traffic Distribution System (TDS). The gated TDS enforces first-visit state, mandatory-click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering and localStorage frequency capping before selectively routing real users to malicious payloads: the RemusStealer infostealer, the AnimateClipper multi-chain crypto clipper, the multi-stage SessionGate loader, and PUA/offer-wall monetization.

How Open-Source/Freeware Impersonation + Click-Hijacking TDS works

Check Point Research (CPR) documented a malware distribution ecosystem that monetizes search traffic for open-source and freeware tooling while serving as a delivery channel for multiple malware families. Operators registered 100+ lookalike domains impersonating developer and security tools (ghidralite.com, dnspy.org, ilspy.org, grpcurl.com, mqttexplorer.com, mfcmapi.com, winsetupfromusb.org, crystaldiskmark.org, guiformat.com) to capture organic search traffic. Each page loads a CloudFront-hosted JavaScript staging layer that intercepts the first eligible user interaction (click/mousedown), calls preventDefault() and stopImmediatePropagation(), and converts a click on the 'download' button into a handoff to a gated Traffic Distribution System (TDS).

The browser-side TDS enforces strict gating: first-visit state checks, mandatory click confirmation, anti-bot and anti-analysis logic, VPN/datacenter filtering, per-client session binding, and localStorage-based frequency capping (capPerDomain, capPerUri, intervalBetweenPops_ms, resetInterval_sec). A decoded config exposed tagId 1230479, redirectorDomain oundhertobeconsist.org and pixelDomain ukentaspectsofc.org. Eligible visitors are routed through a redirector chain (oundhertobeconsist.org/{token}) to offer walls (unlockcontent.org), multi-gate/anti-bot services (trkscope.xyz, file-enter-web.com) and archive delivery hosts (media.stellarcloudhub1.cfd, arch2.maxdatahost1.cyou, mega.nz).

SessionGate is a multi-stage loader engineered to make recovery of the final payload extremely difficult. Stage 1 (NSIS/7-Zip SFX downloader, User-Agent 'NSIS_InetLoad') performs Adler-32/SHA1 hash-table environment checks for EDR/AV drivers (eelam, ehdrv, eamonm, epfwwfp, epfw, ekbdflt, edevmon, npf, npcap, sysmondrv) and Windows Defender registry keys (PUAProtection, MpEnablePus), then beacons to C2 (appfreshstart.com, appgetonline.com, webinnosetup.com, appmakingcenter.com) with a SHA1-based signature scheme. Per-session S3 buckets (s3.us-east-2.amazonaws.com) generate one-time payload URLs (Download_Ready_{id}.exe). Stage 2 embeds an obfuscated ~5MB loader plus ~15MB archive using opaque predicates, junk code and post-branch string encryption, chaining two DLLs with SHA256-derived keys; DLL #1 is an AES-256-CBC key broker (key BFEA4EE8EF934BE7A2B4C64A0BAD1E92, zero IV) contacting CRC C2 domains (yourfastcrc.com, mobileversioncrc.com, webcrcprove.com, integritycrc.com), and DLL #2 is an installer/offer framework pushing PUAs (PDF Spark, PDF Proton, PDF Ignite, NibblrAI, PCPooch).

RemusStealer is a newly emerged infostealer (first underground listing 2026-02-12) delivered as a password-protected ZIP (~14MB) that extracts to an ~850MB zero-padded executable to defeat sandboxes and size-limited scanners. A Go first-stage performs manual PE mapping. It steals from 20+ Chromium and Firefox/NSS browsers and tasks against 332 targeted extensions/applications including 220 crypto wallets (MetaMask, Phantom, Trust Wallet, OKX, Keplr, TronLink, Exodus), 77 password managers (1Password, Bitwarden, LastPass, KeePassXC) and 18 2FA/TOTP tools (Authy, 2FAS). It performs DPAPI key extraction from Local State, clipboard theft (Clipboard.txt), screenshots (Screenshot.bmp), file-system and registry reconnaissance, and exfiltrates over HTTP POST with an access_token UUID and step counter to C2 such as buccstanor.pics:28313, baxe.pics:48261, 217.156.122.75:1378 and 94.231.205.229:28313.

AnimateClipper is a cryptocurrency clipboard hijacker covering 20+ blockchain ecosystems. It is delivered via a ClickFix lure (processing-in-progress-x4.t3.storage.dev) executing mshta.exe against a hex-IP-obfuscated HTA (185.0xA1.0xFB.58/navy.7z), then staged through obfuscated PowerShell (194.150.220.218), a Python/Node.js ZIP, and a node_modules.asar Python loader that runs embedded shellcode in-process via ntdll!LdrCallEnclave and reflectively maps the final PE. It resolves C2 from an on-chain contract (0x6936edc505501EBB2F202C985a021a06f1c10C9E) on BNB Smart Chain Testnet RPC, yielding C2 such as kr.hugo-lapp.co and *.hugo-lapp.lat, and monitors the clipboard to swap victim wallet addresses for attacker-controlled BTC/LTC/XMR/ETH/TRX/XRP/Cosmos/TON addresses. Earliest attacker wallet inbound payment was observed 2025-07-12.

Although the ecosystem is primarily a gray-monetization operation, the same gated TDS that drives ad/PUA revenue selectively routes genuine users to these stealer and clipper payloads, making operators a turnkey distribution channel for downstream malware. CPR telemetry shows 5,000+ related VirusTotal submissions with victims across Turkey, Poland, Brazil, Germany, France, Russia and the UK.

MITRE ATT&CK techniques used in TL-2026-0678

Collection

T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data

Discovery

T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Initial Access

T1189 Drive-by Compromise

execution

T1204 User Execution

stealth

T1218 System Binary Proxy Execution

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Open-Source/Freeware Impersonation + Click-Hijacking TDS

  • N/A — Windows endpoints (search users of open-source/security tooling)
    Vulnerable versions: Windows 10; Windows 11; Windows Server
  • N/A — Chromium-based browsers (Chrome, Edge, Brave, etc.)
    Vulnerable versions: 20+ browser families
  • Mozilla — Firefox / NSS profiles
    Vulnerable versions: all
  • N/A — Browser crypto-wallet / password-manager / 2FA extensions
    Vulnerable versions: 332 targeted extensions/apps

Remediation for Open-Source/Freeware Impersonation + Click-Hijacking TDS

Immediate actions

  • Block the documented impersonation, redirector, CloudFront staging, S3 payload, and C2 domains/IPs at web proxy, DNS and perimeter.
  • Hunt for NSIS_InetLoad User-Agent and Download_Ready_*.exe downloads from s3.us-east-2.amazonaws.com.
  • Alert on mshta.exe spawning from browsers or fetching hex-encoded IP URLs (e.g. 185.0xA1.0xFB.58).

Workarounds

  • Restrict execution of HTA/mshta.exe and unsigned NSIS installers via WDAC/AppLocker.
  • Block outbound traffic to newly registered low-reputation TLDs (.pics, .lat, .cfd, .cyou, .digital) where business need is absent.

Longer-term hardening

  • Deploy EDR with behavioral detection for reflective PE loading, LdrCallEnclave shellcode execution, and clipboard-hijack patterns.
  • Enforce download allow-listing and obtain developer/security tools only from official vendor or distribution channels.
  • Monitor clipboard-replacement of cryptocurrency addresses and deploy address-integrity checks in finance/treasury workflows.

Weaknesses (CWE) in Open-Source/Freeware Impersonation + Click-Hijacking TDS

CWE-494, CWE-829, CWE-451

Timeline of Open-Source/Freeware Impersonation + Click-Hijacking TDS

  • Earliest observed inbound payment to an AnimateClipper attacker-controlled cryptocurrency wallet.
  • Earliest VirusTotal submissions of SessionGate Stage 2 loader samples.
  • FullStory reports the fraudulent impersonation domain cluster; no direct malware abuse identified at that time.
  • Gated TDS scripts embedded into the impersonation-site workflow.
  • Active malware distribution via the TDS infrastructure observed from early January 2026 onward.
  • RemusStealer first appears for sale on an underground forum.
  • Check Point Research publishes the full analysis of the impersonation/click-hijacking/TDS ecosystem.
  • Threadlinqs Intelligence ingests and analyzes the campaign for detection coverage and IOC publication.

Sources cited for Open-Source/Freeware Impersonation + Click-Hijacking TDS

Threats related to Open-Source/Freeware Impersonation + Click-Hijacking TDS

Detection coverage for TL-2026-0678

As of 2026-06-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0678 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats