logo

Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware

ID: 5568b4ea-4485-5629-b2a3-41eb86c3797b

STIX ID: report--5568b4ea-4485-5629-b2a3-41eb86c3797b

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-18

Author: Deeba Ahmed

...
...

Check Point Research uncovered a large network of highly realistic fake download websites impersonating legitimate tools (e.g., Ghidra, dnSpy) that funnel users through CloudFront-hosted JavaScript and a Traffic Distribution System to deliver malware. The operation, active since mid-2025 with broad global reach, distributes multiple threats — notably RemusStealer (Go-based infostealer exfiltrating browser credentials and wallets), AnimateClipper (clipboard hijacker via complex script chains), and SessionGate (obfuscated multi-stage loader) — using sophisticated gating and detection-evasion techniques; several C2 domains and indicators are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.