Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem

June 4, 2026, 9:09 a.m.

Description

A large-scale operation impersonates open-source and freeware projects to capture search traffic, targeting tools such as Ghidra, dnSpy, and SpiderFoot. The professionally designed sites load CloudFront-hosted JavaScript that converts download button clicks into handoffs to a Traffic Distribution System (TDS), which enforces strict gating including first-visit state, click confirmation, anti-bot logic, VPN filtering, and frequency capping. The ecosystem appears primarily built for traffic acquisition and monetization using legitimate ad-tech, but downstream redirect chains repeatedly led selected users to malware delivery infrastructure. The observed payloads include SessionGate (a multi-stage loader with heavy obfuscation delivering potentially unwanted applications), RemusStealer (an infostealer targeting over 20 browsers and hundreds of extensions), and AnimateClipper (a cryptocurrency clipper supporting 20+ blockchain ecosystems). Over 5,000 VirusTotal submissions indicate substantial reach across the ...

Date

  • Created: June 3, 2026, 5:42 p.m.
  • Published: June 3, 2026, 5:42 p.m.
  • Modified: June 4, 2026, 9:09 a.m.

Indicators

  • 598b023e56c45b19173e8f96c1c88036d732fec305cf6bf1b9cf4dbe304beb7f
  • cbad672d9bd06ce91ce465d049e50696fbaec9d209ca0ab1fd814d993d04bc9b
  • 3bb92771e287aa0a8bdd8e5b5bb697427223eaefded3d9b64b5d5c32ad40f3c2
  • ce0888df5e28716432013a8ae002437bd3e993fbe8362c5ff9efbddabfe0ab77
  • 74091f5a8746a1c68d73e1fc1e4e1ff514632ee3f632a8b306f35dabae2d2b64
  • 87361ba2bb412dcf49f8738f3b8b9b7dccb557ad2e76ea8d98ffa5b098ae3886
  • 26f2abfc254a59c2386dd46dca16744f7147a0f0366cb6008e1d53219175f44c
  • e6a1a428a7c09c9946f7c0179d89b263f442dc3208b5144a9146c200e4185bd6
  • 15e6df0c95f2147952308e640d55270e9d097639eaebb34d4b352415f1c6bceb
  • 39dc2327fe1e5a56ac5ad9dc02f0386cff3d83dcfdc558cacba42ebb9dcc5ec2
  • 2e842eab0c16ddd1a2ec4a56610adb58d115b65a1e08e9b67e7e375f8eed0873
  • 4cdb1f7ac502289119f7f8256f00baaa994e6ecfb4000dcf5e1c46073508fcb3
  • 217.156.122.75
  • 194.150.220.218
  • http://intem.lat:9592
  • http://baxe.pics:48261
  • http://oundhertobeconsist.org/
  • http://ropea.top:28313
  • http://gluckcreek.online:48261
  • http://forestoaker.com:6290
  • https://javascriptapiusa.com/lic
  • http://194.150.220.218/4SLEYpfAk57hGubo/fo0suc2ki2.rtf
  • https://cdn-1415.brightcanvas.digital/fo0suc2ki2.rtf
  • http://buccstanor.pics:28313
  • http://buccstanor.pics:48261

Attack Patterns

Additional Informations

  • mobileversioncrc.com
  • cdn-1415.brightcanvas.digital
  • kr.hugo-lapp.co
  • st.hugo-lapp.lat
  • flame-guard.cc
  • ilspy.org
  • forestoaker.com
  • javascriptapiusa.com
  • webinnosetup.com
  • integritycrc.com
  • originaldownloads.info
  • buccstanor.pics
  • winsetupfromusb.org
  • guiformat.com
  • grpcurl.com
  • ghidralite.com
  • ropea.top
  • webcrcprove.com
  • crystaldiskmark.org
  • fd.hugo-lapp.lat
  • appfreshstart.com
  • intem.lat
  • mfcmapi.com
  • io.hugo-lapp.lat
  • ukentaspectsofc.org
  • unlockcontent.org
  • yourfastcrc.com
  • cw.hugo-lapp.lat
  • carlessclapped.com
  • ed.hugo-lapp.lat
  • td.hugo-lapp.lat
  • arch2.maxdatahost1.cyou
  • appmakingcenter.com
  • gluckcreek.online
  • processing-in-progress-x4.t3.storage.dev
  • media.stellarcloudhub1.cfd
  • mqttexplorer.com
  • dnspy.org
  • appgetonline.com
  • Brazil
  • Poland
  • United Kingdom of Great Britain and Northern Ireland
  • Germany
  • France
  • Russian Federation