Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive
Check Point Research uncovered¹ a large-scale operation that impersonated open-source and freeware projects to capture search traffic. The convincing fake project portals loaded a CloudFront-hosted JavaScript staging layer that rerouted download clicks into a strictly gated traffic distribution system (TDS). Downstream redirect chains then steered selected users to malware delivery infrastructure for RemusStealer, AnimateClipper, and the SessionGate framework.
The original analysis publicized 27 network IoCs. Aided by the WhoisXML API MCP Server², we investigated 30 IoCs—eight subdomains, 19 domains, and three IP addresses—after extracting the unique apex domains from the subdomain IoCs and running domain legitimacy and activity checks.
Original IoCs Analyzed
Domains, IPs, subdomains, and related indicators
Key Findings
Additional IP address
IP-connected domains
Malicious Articfacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Subdomain IoCs malicious infrastructure check
- Domain IoCs WHOIS and DNS history analysis
- IP IoCs geolocation and traffic analysis
- Email-connected domain discovery
- IP-connected domain discovery
- Malicious artifact confirmation
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/
- [2] https://main.whoisxmlapi.com/ai/mcp-server