Open-Source/Freeware Impersonation + Click-Hijacking TDS Ecosystem Delivering RemusStealer, AnimateClipper & SessionGate — Threadlinqs Intelligence
As of 2026-06-04, Open-Source/Freeware Impersonation + Click-Hijacking TDS Ecosystem Delivering RemusStealer, AnimateClipper & SessionGate is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-0678 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Check Point Research exposed a large-scale distribution ecosystem of 100+ websites impersonating open-source and security tooling (Ghidra, dnSpy, ILSpy, SpiderFoot lookalikes) that load
Check Point Research (CPR) documented a malware distribution ecosystem that monetizes search traffic for open-source and freeware tooling while serving as a delivery channel for multiple malware families. Operators registered 100+ lookalike domains impersonating developer and security tools (ghidralite.com, dnspy.org, ilspy.org, grpcurl.com, mqttexplorer.com, mfcmapi.com, winsetupfromusb.org, crystaldiskmark.org, guiformat.com) to capture organic search traffic. Each page loads a CloudFront-hosted JavaScript staging layer that intercepts the first eligible user interaction (click/mousedown), calls preventDefault() and stopImmediatePropagation(), and converts a click on the 'download' button into a handoff to a gated Traffic Distribution System (TDS).
The browser-side TDS enforces strict gating: first-visit state checks, mandatory click confirmation, anti-bot and anti-analysis logic, VPN/datacenter filtering, per-client session binding, and localStorage-based frequency capping (capPerDomain, capPerUri, intervalBetweenPops_ms, resetInterval_sec). A decoded config exposed tagId 1230479, redirectorDomain oundhertobeconsist.org and pixelDomain ukentaspectsofc.org. Eligible visitors are routed through a redirector chain (oundhertobeconsist.org/{token}) to offer walls (unlockcontent.org), multi-gate/anti-bot services (trkscope.xyz, file-enter-web.com) and archive delivery hosts (media.stellarcloudhub1.cfd, arch2.maxdatahost1.cyou, mega.nz).
SessionGate is a multi-stage loader engineered to make recovery of the final payload extremely difficult. Stage 1 (NSIS/7-Zip SFX downloader, User-Agent 'NSIS_InetLoad') performs Adler-32/SHA1 hash-table environment checks for EDR/AV drivers (eelam, ehdrv, eamonm, epfwwfp, epfw, ekbdflt, edevmon, npf, npcap, sysmondrv) and Windows Defender registry keys (PUAProtection, MpEnablePus), then beacons to C2 (appfreshstart.com, appgetonline.com, webinnosetup.com, appmakingcenter.com) with a SHA1-based signature scheme. Per-session S3 buckets (s3.us-east-2.amazonaws.com) generate one-time payload URLs (Download_Ready_{id}.exe). Stage 2 embeds an obfuscated ~5MB loader plus ~15MB archive using opaque predicates, junk code and post-branch string encryption, chaining two DLLs with SHA256-derived keys; DLL #1 is an AES-256-CBC key broker (key BFEA4EE8EF934BE7A2B4C64A0BAD1E92, zero IV) contacting CRC C2 domains (yourfastcrc.com, mobileversioncrc.com, webcrcprove.com, integritycrc.com), and DLL #2 is an installer/offer framework pushing PUAs (PDF Spark, PDF Proton, PDF Ignite, NibblrAI, PCPooch).
RemusStealer is a newly emerged infostealer (first underground listing 2026-02-12) delivered as a password-protected ZIP (~14MB) that extracts to an ~850MB zero-padded executable to defeat sandboxes and size-limited scanners. A Go first-stage performs manual PE mapping. It steals from 20+ Chromium and Firefox/NSS browsers and tasks against 332 targeted extensions/applications including 220 crypto wallets (MetaMask, Phantom, Trust Wallet, OKX, Keplr, TronLink, Exodus), 77 password managers (1Password, Bitwarden, LastPass, KeePassXC) and 18 2FA/TOTP tools (Authy, 2FAS). It performs DPAPI key extraction from Local State, clipboard theft (Clipboard.txt), screenshots (Screenshot.bmp), file-system and registry reconnaissance, and exfiltrates over HTTP POST with an access_token UUID and step counter to C2 such as buccstanor.pics:28313, baxe.pics:48261, 217.156.122.75:1378 and 94.231.205.229:28313.
AnimateClipper is a cryptocurrency clipboard hijacker covering 20+ blockchain ecosystems. It is delivered via a ClickFix lure (processing-in-progress-x4.t3.storage.dev) executing mshta.exe against a hex-IP-obfuscated HTA (185.0xA1.0xFB.58/navy.7z), then staged through obfuscated PowerShell (194.150.220.218), a Python/Node.js ZIP, and a node_modules.asar Python loader that runs embedded shellcode in-process via ntdll!LdrCallEnclave and reflectively maps the final PE. It resolves C2 from an on-chain contract (0x6936edc505501EBB2F2
Weaknesses (CWE)
CWE-494, CWE-829, CWE-451
Target sectors: technology, software-development, security-research, cryptocurrency, finance, consumer
Target regions: Europe, South America, Middle East, North America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1189, T1204, T1059, T1059, T1218, T1620, T1027, T1497