Skip to main content
Mallory
Back to intelligence
search-ad-manipulationcredential-stealer-activityloader-delivery-mechanismpayload-delivery-evasion

Fake Open-Source Download Sites Funnel Victims to TDS and Malware

Updated 1d agoFirst seen Jun 3, 20264 sources

A large-scale campaign has impersonated popular open-source and freeware projects, including Ghidra, dnSpy, and SpiderFoot, to capture search traffic and hijack software download clicks. Researchers found that the fake sites use CloudFront-hosted JavaScript to intercept a visitor’s first interaction and send users into a gated Traffic Distribution System (TDS) that performs anti-bot screening, VPN and datacenter filtering, click confirmation, and frequency capping before deciding what content to serve.

The infrastructure appears primarily built for traffic acquisition and monetization, but selected victims were repeatedly routed into malware delivery chains. Those chains included SessionGate, a heavily obfuscated multi-stage framework with strong anti-analysis protections that mainly delivered potentially unwanted applications, as well as RemusStealer and AnimateClipper, which were used to deploy an infostealer and a cryptocurrency clipper. Researchers said the operation has been active since at least late 2025, with active malware distribution observed from early 2026 and more than 5,000 VirusTotal submissions indicating significant scale.

Share:
Fake Open-Source Download Sites Funnel Victims to TDS and Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 3, 20263d ago

Active malware delivery observed through the fake-site ecosystem

Researchers observed active malware distribution from early January 2026, with selected users routed through a gated traffic distribution system into delivery chains involving SessionGate, RemusStealer, and AnimateClipper.

Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem - Check Point Research

Campaign begins impersonating open-source and freeware projects

Check Point Research reported that the malware distribution ecosystem had been active since at least late 2025, using fake sites that impersonated popular open-source and freeware projects to capture search traffic and hijack download clicks.

Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem - Check Point Research

Check Point Research publishes analysis of the distribution ecosystem

On 2026-06-03, Check Point Research published its analysis describing the impersonation campaign, click hijacking via CloudFront-hosted JavaScript, and the TDS-based routing and malware monetization ecosystem behind it.

Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem - Check Point Research
Sep 1, 20259mo ago

Infrastructure activity traced back to September 2025

Check Point assessed that the fake-site infrastructure was active as early as September 2025, initially operating as a traffic acquisition and monetization scheme before being repurposed for malware delivery later. This pushes the known start of the ecosystem earlier than previously captured in the timeline.

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Fake Open-Source Download Sites Funnel Victims to TDS and Malware | Mallory