AUTO-UPDATED

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

Cybersecurity researchers have identified a sophisticated campaign using deceptive websites to impersonate open-source projects and distribute malware like Remus Stealer through a complex traffic distribution system.

Key Points

  • Attackers mimic legitimate tools like Ghidra and dnSpy to rank highly in Google search results and deceive users.
  • A gated Traffic Distribution System (TDS) uses anti-bot and anti-analysis logic to filter users before delivering malicious payloads.
  • Malware families identified in the campaign include the SessionGate loader, Remus Stealer, and the AnimateClipper cryptocurrency hijacker.
  • The operation has been active since September 2025, with malicious payload distribution beginning in January 2026.
  • VirusTotal telemetry shows thousands of submissions for the SessionGate loader, primarily originating from Europe, Russia, and Brazil.

Why it Matters

This campaign highlights the growing risk of "malvertising" and search engine poisoning, where attackers exploit the trust users place in popular open-source software. By combining legitimate-looking portals with advanced evasion techniques, these operators can effectively compromise systems while remaining difficult for security analysts to track.
Internet Published by info@thehackernews.com (The Hacker News)
Read original