logo

Hackers Impersonate Ghidra, dnSpy, and SpiderFoot to Spread Malware

ID: f63df767-d5fe-53f0-b6aa-33e777588678

STIX ID: report--f63df767-d5fe-53f0-b6aa-33e777588678

Feed Name: Cyber Press

Threat Score
82/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Varshini

...
...

Researchers uncovered a large-scale campaign where threat actors stood up professionally designed fake websites for popular open-source tools (e.g., Ghidra, dnSpy, SpiderFoot) that use click-hijacking and Traffic Distribution Systems (hosted on legitimate CDNs) to filter and redirect victims to malicious payloads. The infrastructure dynamically gates victims by location, OS, browser and other signals to evade researchers, and delivers sophisticated multi-stage malware such as the obfuscated SessionGate loader and the RemusStealer infostealer that targets dozens of browsers, extensions, and cryptocurrency credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.