logo

Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem

ID: 8a87b676-b7e7-52dd-8005-d7d3147c7a7a

STIX ID: report--8a87b676-b7e7-52dd-8005-d7d3147c7a7a

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: stcpresearch

...
...

Check Point Research analyzed a large-scale campaign of professionally crafted impersonation websites for open-source and freeware projects that intercept first-click downloads and funnel victims into a gated Traffic Distribution System (TDS). The TDS performs anti-analysis and filtering before routing select victims to downstream payloads — notably a multi-stage, heavily gated loader (SessionGate), the RemusStealer infostealer, and an AnimateClipper crypto-clipper — with per-session keys, server-side gating, and monetization-driven distribution; the report includes technical workflow diagrams, detailed module behavior, and extensive IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.