#AnimateClipper
Fake open-source tool sites are distributing malware via advanced TDS. Verify sources before downloading. #CyberSecurity #Malware #OpenSource #TDS #RemusStealer #AnimateClipper thedailytechfeed.com/malicious-si...
June 4, 2026 at 10:24 AM
Check Point Research found 100+ fake sites impersonating Ghidra, dnSpy, and SpiderFoot, using click hijacking and TDS gates to spread SessionGate, RemusStealer, and AnimateClipper. #Ghidra #dnSpy #SpiderFoot
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Check Point Research exposed a large-scale campaign that impersonates trusted open-source and freeware projects such as Ghidra, dnSpy, and SpiderFoot to hijack download clicks and route users through a gated Traffic Distribution System. The same infrastructure was used to deliver SessionGate, RemusStealer, and AnimateClipper, showing that the operation mixed traffic monetization with downstream malware delivery. #Ghidra #dnSpy #SpiderFoot #SessionGate #RemusStealer #AnimateClipper
www.hendryadrian.com
June 3, 2026 at 7:45 PM
🚨 Fake software portals weaponize the first click

Check Point found 100+ impersonation sites using CloudFront-hosted TDS scripts to redirect downloads toward RemusStealer, AnimateClipper and SessionGate.

🔗 read more: research.checkpoint.com/2026/imperso...

#ransomNews #cybersecurity
June 4, 2026 at 11:37 AM
HBO Max's verified Reddit account was hijacked to post 108 malicious ads in 48 hours, using ClickFix pages to infect Windows and macOS with info-stealing malware and fake AI, dev, and crypto apps. #HBOMax #PasteSwitch #AMOS
Hackers Hijack HBO Max Reddit Account To Push Malware In ClickFix Ads
Hackers hijacked HBO Max’s official Reddit account to run malicious ads that led users to ClickFix pages and infected Windows and macOS devices with information-stealing malware. The campaign, linked by researchers to PasteSwitch, also pushed fake AI tools, developer software, and cryptocurrency wallet apps to steal credentials and wallet recovery phrases. #HBOMax #PasteSwitch #MacSync #AMOS #AmateraStealer #AnimateClipper #ZigClipper
www.hendryadrian.com
September 15, 2026 at 12:30 AM
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施

偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施
偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
blackhatnews.tokyo
June 4, 2026 at 10:05 AM
A compromised verified HBO Max Reddit account ran 108 PasteSwitch ClickFix ads in 48 hours, pushing fake macOS and Windows installers that delivered MacSync, AMOS, Amatera Stealer, and crypto clippers. #HBOMax #PasteSwitch #ClickFix
HBO Max Ads On A Compromised Reddit Account Exposed A Massive PasteSwitch ClickFix Operation
A compromised verified Reddit account for HBO Max was used for 48 hours to run a massive PasteSwitch ClickFix malvertising campaign, pushing 108 deceptive ads that led users to fake macOS and Windows installers. The operation delivered MacSync, AMOS, Amatera Stealer, and cryptocurrency clippers through cross-platform lures, deceptive TLS tactics, and smart contract-based C2 infrastructure. #HBOMax #PasteSwitch #ClickFix #MacSync #AMOS #AmateraStealer #AnimateClipper #ZigClipper #Reddit
www.hendryadrian.com
September 14, 2026 at 5:30 PM
Check Point Research exposed fake open-source and freeware sites that hijacked search traffic through click-driven redirects, sending selected users to RemusStealer, AnimateClipper, and SessionGate. #ClickFix #TDS #CloudFront
Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive
Check Point Research uncovered a large-scale operation that impersonated open-source and freeware projects to capture search traffic through deceptive sites and click-driven redirects. The traffic was funneled through a CloudFront-hosted JavaScript staging layer and TDS chains that ultimately pointed selected users to RemusStealer, AnimateClipper, and the SessionGate framework. #CheckPointResearch #CloudFront #RemusStealer #AnimateClipper #SessionGate
www.hendryadrian.com
July 27, 2026 at 11:45 PM
📢 Écosystème de distribution de malwares via TDS, usurpation d'identité et détournement de clics
📝 ## 🔍 Contexte

Publié le 3 juin 2026…
https://cyberveille.ch/posts/2026-06-07-ecosysteme-de-distribution-de-malwares-via-tds-usurpation-d-identite-et-detournement-de-clics/ #AnimateClipper #Cyberveille
June 7, 2026 at 6:00 PM
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and de…
#hackernews #news
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. "The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing
thehackernews.com
June 5, 2026 at 5:29 AM
Cybersecurity alert: scammers mimic open-source sites to lure users into a Traffic Distribution System, spreading malware like Remus Stealer, AnimateClipper, and SessionGate. Stay vigilant!
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
A large-scale campaign impersonates open-source and freeware project portals to redirect users through a gated TDS and deliver malware.
thehackernews.com
June 7, 2026 at 11:30 PM
~Checkpoint~
Fake open-source tool sites use click hijacking and TDS to deliver SessionGate, RemusStealer, and AnimateClipper.
-
IOCs: appfreshstart[. ]com, buccstanor[. ]pics, kr[. ]hugo-lapp[. ]co
-
#Malware #TDS #ThreatIntel
Malware Distribution via Impersonation & TDS
research.checkpoint.com
June 3, 2026 at 4:05 PM