Fake Ghidra, dnSpy & SpiderFoot Sites Used to Spread Malware
ID: c00c1a4e-db20-5739-ae49-1270ed551791
STIX ID: report--c00c1a4e-db20-5739-ae49-1270ed551791
Feed Name: GBHackers
**Malicious cloned download portals distribute malware via a click‑hijacking TDS:** Operators clone legitimate tool websites (e.g., Ghidra, dnSpy, SpiderFoot) and inject CloudFront JavaScript that intercepts the first download click to route victims through a stateful traffic distribution system, resulting in delivery of SessionGate (a sophisticated multi‑stage loader), RemusStealer infostealer, AnimateClipper crypto‑clipper, or PUAs; the report includes numerous IOCs and highlights the need to validate download sources and monitor DNS/script behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
