Check Point Research uncovered a large-scale operation that impersonated open-source and freeware projects to capture search traffic through deceptive sites and click-driven redirects. The traffic was funneled through a CloudFront-hosted JavaScript staging layer and TDS chains that ultimately pointed selected users to RemusStealer, AnimateClipper, and the SessionGate framework. #CheckPointResearch #CloudFront #RemusStealer #AnimateClipper #SessionGate
Keypoints
- The operation used fake project portals that looked legitimate at a glance to lure users searching for open-source and freeware projects.
- Deception relied on user interaction, with clicks triggering redirects rather than malicious content being obvious on the page itself.
- A CloudFront-hosted JavaScript staging layer redirected traffic into a traffic distribution system (TDS) with strict gating.
- The downstream redirect chains were associated with malware delivery infrastructure for RemusStealer, AnimateClipper, and the SessionGate framework.
- Researchers identified 27 network IoCs initially, then expanded this to 30 IoCs consisting of subdomains, domains, and IP addresses.
- DNS and WHOIS analysis revealed typosquatting groups, likely malicious registrations, victim-related IP activity, and thousands of email-connected domains.
- Several artifacts remained active at the time of reporting, indicating the infrastructure was still operational in parts.
MITRE Techniques
- [T1036 ] Masquerading – The actors impersonated legitimate open-source and freeware project portals to mislead users. [‘well-designed sites often looked like legitimate project portals at a glance’]
- [T1204 ] User Execution – Malicious redirects were triggered through user clicks and other interactions. [‘the deception… was spurred by user interactions’ and ‘redirected user clicks’]
- [T1090 ] Proxy – A traffic distribution system and redirect chain were used to route selected users toward different infrastructure. [‘redirected user clicks to a traffic distribution system (TDS) with strict gating features’]
- [T1583.001 ] Acquire Infrastructure: Domains – The campaign used numerous domains and subdomains as part of its malicious ecosystem. [’27 network IoCs made up of subdomains, domains, and IP addresses’]
- [T1583.004 ] Acquire Infrastructure: Server – CloudFront-hosted infrastructure was used as part of the staging and delivery chain. [‘loaded a CloudFront-hosted JavaScript staging layer’]
- [T1566 ] Phishing – The operation imitated trusted software projects to lure search traffic and users into a malicious redirect flow. [‘impersonating open-source and freeware projects to capture search traffic’]
Indicators of Compromise
- [Domains/Subdomains ] Suspicious project-impersonation infrastructure and typosquatting groups – brightcanvas[.]digital, hugo-lapp[.]lat, ropea[.]top, rosca[.]cn, and 4 more look-alike domains
- [IP Addresses ] Infrastructure and victim-related communication – 217[.]156[.]122[.]75, one client IP address that queried a domain IoC, and 22 unique victim-like IPs communicating with two IP IoCs
- [Email Addresses ] Historical WHOIS records linked to expanded domain sets – 22 unique email addresses, 3 public email addresses, and other 19 items
- [DNS Resolutions ] Historical domain-to-IP and IP-to-domain mappings – 181 historical domain-to-IP resolutions, 333 historical IP-to-domain resolutions, and examples such as ropea[.]top and webcrcprove[.]com
- [Malicious Domains ] Email-connected and flagged domains – 2,892 email-connected domains, 11 confirmed malicious, plus 26 additional malicious IP addresses and 23 IP-connected domains
- [File Names ] No file hashes or file names were provided in the article.
Read more: https://circleid.com/posts/inside-a-tds-powered-clickfix-malware-ecosystem-a-dns-deep-dive