logo

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

ID: 69db5eac-6e46-5428-8383-332204031dbb

STIX ID: report--69db5eac-6e46-5428-8383-332204031dbb

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: [email protected] (The Hacker News)

...
...

Malicious actors are impersonating legitimate open-source and freeware project portals and leveraging SEO poisoning and click-interception to funnel users into a CloudFront-hosted JavaScript staging layer that hands off to a gated Traffic Distribution System (TDS). The TDS implements anti-bot/anti-analysis checks and selectively delivers multi-stage payloads — notably the SessionGate obfuscated loader, Remus Stealer (infostealer), and AnimateClipper (cryptocurrency clipper) — with evidence of active distribution since January 2026 and several thousand related VirusTotal submissions from multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.