Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
June 4, 2026, 9:09 a.m.
Description
A large-scale operation impersonates open-source and freeware projects to capture search traffic, targeting tools such as Ghidra, dnSpy, and SpiderFoot. The professionally designed sites load CloudFront-hosted JavaScript that converts download button clicks into handoffs to a Traffic Distribution System (TDS), which enforces strict gating including first-visit state, click confirmation, anti-bot logic, VPN filtering, and frequency capping. The ecosystem appears primarily built for traffic acquisition and monetization using legitimate ad-tech, but downstream redirect chains repeatedly led selected users to malware delivery infrastructure. The observed payloads include SessionGate (a multi-stage loader with heavy obfuscation delivering potentially unwanted applications), RemusStealer (an infostealer targeting over 20 browsers and hundreds of extensions), and AnimateClipper (a cryptocurrency clipper supporting 20+ blockchain ecosystems). Over 5,000 VirusTotal submissions indicate substantial reach across the ...
Tags
Date
- Created: June 3, 2026, 5:42 p.m.
- Published: June 3, 2026, 5:42 p.m.
- Modified: June 4, 2026, 9:09 a.m.
Indicators
- 598b023e56c45b19173e8f96c1c88036d732fec305cf6bf1b9cf4dbe304beb7f
- cbad672d9bd06ce91ce465d049e50696fbaec9d209ca0ab1fd814d993d04bc9b
- 3bb92771e287aa0a8bdd8e5b5bb697427223eaefded3d9b64b5d5c32ad40f3c2
- ce0888df5e28716432013a8ae002437bd3e993fbe8362c5ff9efbddabfe0ab77
- 74091f5a8746a1c68d73e1fc1e4e1ff514632ee3f632a8b306f35dabae2d2b64
- 87361ba2bb412dcf49f8738f3b8b9b7dccb557ad2e76ea8d98ffa5b098ae3886
- 26f2abfc254a59c2386dd46dca16744f7147a0f0366cb6008e1d53219175f44c
- e6a1a428a7c09c9946f7c0179d89b263f442dc3208b5144a9146c200e4185bd6
- 15e6df0c95f2147952308e640d55270e9d097639eaebb34d4b352415f1c6bceb
- 39dc2327fe1e5a56ac5ad9dc02f0386cff3d83dcfdc558cacba42ebb9dcc5ec2
- 2e842eab0c16ddd1a2ec4a56610adb58d115b65a1e08e9b67e7e375f8eed0873
- 4cdb1f7ac502289119f7f8256f00baaa994e6ecfb4000dcf5e1c46073508fcb3
- 217.156.122.75
- 194.150.220.218
- http://intem.lat:9592
- http://baxe.pics:48261
- http://oundhertobeconsist.org/
- http://ropea.top:28313
- http://gluckcreek.online:48261
- http://forestoaker.com:6290
- https://javascriptapiusa.com/lic
- http://194.150.220.218/4SLEYpfAk57hGubo/fo0suc2ki2.rtf
- https://cdn-1415.brightcanvas.digital/fo0suc2ki2.rtf
- http://buccstanor.pics:28313
- http://buccstanor.pics:48261
Additional Informations
- mobileversioncrc.com
- cdn-1415.brightcanvas.digital
- kr.hugo-lapp.co
- st.hugo-lapp.lat
- flame-guard.cc
- ilspy.org
- forestoaker.com
- javascriptapiusa.com
- webinnosetup.com
- integritycrc.com
- originaldownloads.info
- buccstanor.pics
- winsetupfromusb.org
- guiformat.com
- grpcurl.com
- ghidralite.com
- ropea.top
- webcrcprove.com
- crystaldiskmark.org
- fd.hugo-lapp.lat
- appfreshstart.com
- intem.lat
- mfcmapi.com
- io.hugo-lapp.lat
- ukentaspectsofc.org
- unlockcontent.org
- yourfastcrc.com
- cw.hugo-lapp.lat
- carlessclapped.com
- ed.hugo-lapp.lat
- td.hugo-lapp.lat
- arch2.maxdatahost1.cyou
- appmakingcenter.com
- gluckcreek.online
- processing-in-progress-x4.t3.storage.dev
- media.stellarcloudhub1.cfd
- mqttexplorer.com
- dnspy.org
- appgetonline.com
- Brazil
- Poland
- United Kingdom of Great Britain and Northern Ireland
- Germany
- France
- Russian Federation