惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
N
Netflix TechBlog - Medium
WordPress大学
WordPress大学
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
V
Visual Studio Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
Hugging Face - Blog
Hugging Face - Blog
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
博客园 - 【当耐特】
B
Blog
Stack Overflow Blog
Stack Overflow Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
GbyAI
GbyAI
博客园 - 司徒正美
博客园 - 叶小钗
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
From Stars to Upvotes: The Fake Reputation Economy Behind...
anap · 2026-06-17 · via Check Point Blog

Key Findings

  • Trust is being manufactured at scale. A single threat actor built a cross-platform ecosystem: a WordPress phishing hub, GitHub and SourceForge projects, a YouTube channel, crypto forums, and even posts on legitimate news sites, all engineered to make a malicious “tool” look popular, vetted, and safe
  • Reputation systems themselves are now a target. The actor seeds benign votes and “safe” community comments on VirusTotal samples that already carry low detection rates, nudging reputation-based defenses toward misclassifying clearly malicious files as harmless
  • AI is woven into the lure. Fake “tutorial” videos pair real-looking desktop demos with AI-generated narrators and artificially inflated view counts to build a convincing illusion of a satisfied user base
  • Real reach, manufactured scale. Over 5,000 GitHub downloads (1,250+ on macOS) point to genuine impact, while a SourceForge counter inflated to 44,485 and a payload carrying 15,500+ attacker wallets show how aggressively the operation was built to look bigger than it was
  • Windows and macOS are both targeted, with self-healing persistence on Mac designed to survive manual removal

A Threat Built on Fabricated Trust

Most malware campaigns try to hide. This one does the opposite, it works hard to look loved.

Check Point Research analyzed a cryptocurrency clipboard hijacker (a “clipper”) hidden inside a collection of “tools” that promise users an unfair edge: Solana and Pump.fun sniper bots, an “Aviator Predictor,” and various crash-game predictors. The targets are crypto holders and online gamblers already hunting for shortcuts and quick, automated profits.

What makes the campaign notable isn’t the malware — clippers are old news. It’s that the attacker behaves less like a hacker than a marketer. To push a malicious “tool,” a single threat actor borrowed the same playbook legitimate brands use to build buzz: inflated download counts, coordinated five-star reviews, influencer-style tutorial videos, and promotion on platforms people instinctively trust. The result is a fake reputation economy spanning every platform a curious victim might check before they click “download.”

Manufacturing Popularity: Ghost Networks Everywhere

The illusion runs on Ghost Networks: clusters of fake or low-quality accounts that exist to inflate the signals people instinctively trust.

On GitHub, at least six linked accounts cross-promote one another’s repositories, racking up stars, forks, and downloads from controlled accounts. This follows the same pattern Check Point Research documented on GitHub Ghost Networks. One repository alone displayed 146 stars and 62 forks. On SourceForge, the download counter reached 44,485, with a suspicious 37,460 supposedly originating from Android devices, despite the developer only offering Windows and macOS versions. A plausible explanation is the use of an Android farm to artificially inflate the download count on SourceForge.

On YouTube, the same playbook plays out with YouTube Ghost Networks driving unnatural spikes in views and a comment section full of glowing, coordinated praise. The videos are styled as authentic personal walkthroughs, complete with a synthetic, AI-generated narrator guiding the viewer step by step.

The New Frontier: Poisoning Reputation Systems

The most consequential evolution in this campaign isn’t aimed at people at all. It’s aimed at the tools that defend them.

Check Point Research observed accounts casting benign votes and posting “safe” comments on the campaign’s samples on VirusTotal, a platform that aggregates detections from dozens of security engines and feeds the reputation models many organizations rely on. The positive engagement doesn’t cause the low detection rates, but the combination is the point: a malicious file with few detections and a chorus of “looks clean” feedback creates a powerful, false impression of safety that can sway both end users and automated, reputation-based decisions.

In other words, attackers are no longer just trying to evade detection. They’re trying to manipulate the global trust signals that detection increasingly depends on.

The campaign rounds this out with posts on long-standing crypto communities like BitcoinTalk, meeting the target audience exactly where they already gather.

The Payload: A Cross-Platform Clipboard Hijacker

Behind all the social proof, the actual malware is straightforward. Both the Windows and macOS payloads are Rust-based clippers. Once running, they quietly install persistence and monitor the clipboard for anything resembling a cryptocurrency wallet address: Bitcoin, Ethereum, Litecoin, Tron, XRP, Cardano, and more. When a match appears, the malware silently swaps it for an attacker-controlled address pulled from a large embedded list.

Why This Matters

This campaign may not be aimed at large enterprises, but the technique it showcases is the part worth watching. Manipulating sentiment and reputation across crowd-sourced platforms marks a meaningful shift in how attackers build trust. The same playbook of fake reputation and aggressive cross-platform promotion can easily distribute information stealers or ransomware to higher-value targets over time.

What Defenders and Users Should Do

  • Don’t trust engagement metrics as a proxy for safety. Stars, forks, download counts, view spikes, and “safe” comments can all be bought or faked. Popularity is not a security signal
  • Be deeply skeptical of “edge” tools. Sniper bots, game predictors, and anything promising guaranteed crypto gains are classic bait
  • Treat reputation scores as one input, not a verdict. A low detection rate paired with positive community sentiment can be manufactured. Combine reputation data with behavioral detection and your own telemetry.
  • For macOS users: never run an “unlocker” or instructions that tell you to bypass Gatekeeper warnings. That step is the attack.

Check Point’s Workspace Security provides protection against the clipboard hijacker variants identified in this research.

For the full technical breakdown read the complete Check Point Research report.