logo

Fake Ghidra, dnSpy & SpiderFoot Sites Used to Spread Malware

ID: c00c1a4e-db20-5739-ae49-1270ed551791

STIX ID: report--c00c1a4e-db20-5739-ae49-1270ed551791

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Mayura Kathir

...
...

**Malicious cloned download portals distribute malware via a click‑hijacking TDS:** Operators clone legitimate tool websites (e.g., Ghidra, dnSpy, SpiderFoot) and inject CloudFront JavaScript that intercepts the first download click to route victims through a stateful traffic distribution system, resulting in delivery of SessionGate (a sophisticated multi‑stage loader), RemusStealer infostealer, AnimateClipper crypto‑clipper, or PUAs; the report includes numerous IOCs and highlights the need to validate download sources and monitor DNS/script behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.