#sessiongate
Check Point Research found 100+ fake sites impersonating Ghidra, dnSpy, and SpiderFoot, using click hijacking and TDS gates to spread SessionGate, RemusStealer, and AnimateClipper. #Ghidra #dnSpy #SpiderFoot
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Check Point Research exposed a large-scale campaign that impersonates trusted open-source and freeware projects such as Ghidra, dnSpy, and SpiderFoot to hijack download clicks and route users through a gated Traffic Distribution System. The same infrastructure was used to deliver SessionGate, RemusStealer, and AnimateClipper, showing that the operation mixed traffic monetization with downstream malware delivery. #Ghidra #dnSpy #SpiderFoot #SessionGate #RemusStealer #AnimateClipper
www.hendryadrian.com
June 3, 2026 at 7:45 PM
🚨 Fake software portals weaponize the first click

Check Point found 100+ impersonation sites using CloudFront-hosted TDS scripts to redirect downloads toward RemusStealer, AnimateClipper and SessionGate.

🔗 read more: research.checkpoint.com/2026/imperso...

#ransomNews #cybersecurity
June 4, 2026 at 11:37 AM
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施

偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施
偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
blackhatnews.tokyo
June 4, 2026 at 10:05 AM
Check Point Research exposed fake open-source and freeware sites that hijacked search traffic through click-driven redirects, sending selected users to RemusStealer, AnimateClipper, and SessionGate. #ClickFix #TDS #CloudFront
Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive
Check Point Research uncovered a large-scale operation that impersonated open-source and freeware projects to capture search traffic through deceptive sites and click-driven redirects. The traffic was funneled through a CloudFront-hosted JavaScript staging layer and TDS chains that ultimately pointed selected users to RemusStealer, AnimateClipper, and the SessionGate framework. #CheckPointResearch #CloudFront #RemusStealer #AnimateClipper #SessionGate
www.hendryadrian.com
July 27, 2026 at 11:45 PM
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and de…
#hackernews #news
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. "The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing
thehackernews.com
June 5, 2026 at 5:29 AM
Cybersecurity alert: scammers mimic open-source sites to lure users into a Traffic Distribution System, spreading malware like Remus Stealer, AnimateClipper, and SessionGate. Stay vigilant!
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
A large-scale campaign impersonates open-source and freeware project portals to redirect users through a gated TDS and deliver malware.
thehackernews.com
June 7, 2026 at 11:30 PM
~Checkpoint~
Fake open-source tool sites use click hijacking and TDS to deliver SessionGate, RemusStealer, and AnimateClipper.
-
IOCs: appfreshstart[. ]com, buccstanor[. ]pics, kr[. ]hugo-lapp[. ]co
-
#Malware #TDS #ThreatIntel
Malware Distribution via Impersonation & TDS
research.checkpoint.com
June 3, 2026 at 4:05 PM