Cybersecurity researchers have identified a sophisticated campaign using deceptive websites to impersonate open-source projects and distribute malware like Remus Stealer through a complex traffic distribution system.
Key Points
- Attackers mimic legitimate tools like Ghidra and dnSpy to rank highly in Google search results and deceive users.
- A gated Traffic Distribution System (TDS) uses anti-bot and anti-analysis logic to filter users before delivering malicious payloads.
- Malware families identified in the campaign include the SessionGate loader, Remus Stealer, and the AnimateClipper cryptocurrency hijacker.
- The operation has been active since September 2025, with malicious payload distribution beginning in January 2026.
- VirusTotal telemetry shows thousands of submissions for the SessionGate loader, primarily originating from Europe, Russia, and Brazil.