news.mlab.sh
Back to the feed
malware

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

High
Summary

A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, including the SessionGate loader, Remus Stealer, and AnimateClipper, designed to steal data and disrupt user activity. The campaign leverages Google search rankings to maximize visibility and has recently begun distributing malware, indicating a shift in tactics.

This campaign, identified by Check Point researchers, utilizes a deceptive strategy to generate traffic for malicious websites. The attackers create fake websites that closely resemble legitimate open-source projects, often referencing real upstream resources to build trust. When a user interacts with a 'download' button on these sites, a CloudFront-hosted JavaScript layer redirects them to a Traffic Distribution System (TDS). This TDS employs stringent gating mechanisms, including bot detection, VPN filtering, and frequency capping, to control the flow of traffic and ensure users are directed to the malware delivery infrastructure. The operation’s primary objective appears to be traffic acquisition and monetization, capitalizing on the popularity of trusted tools like Ghidra, dnSpy, and SpiderFoot, which are frequently used by security professionals and developers.

The campaign has been ongoing since September 2025, with evidence of Google search rankings being manipulated to surface the fake sites prominently. Recent findings show that the TDS scripts were embedded shortly after, and the infrastructure was repurposed for malware distribution starting January 2026. The malware delivered includes SessionGate, a multi-stage loader with anti-analysis capabilities, Remus Stealer, a new information stealer offered as a service, and AnimateClipper, a cryptocurrency clipper. Analysis of VirusTotal telemetry reveals approximately 2,000 to 3,500 submissions of SessionGate samples, originating primarily from Turkey, Poland, Brazil, Germany, France, Russia, and the U.K. The final stage of the attack chain involves executing a DLL payload that communicates with an external server to retrieve an encrypted configuration and silently execute the next-stage malware.

Read the full article at The Hacker News