Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware
ID: 5568b4ea-4485-5629-b2a3-41eb86c3797b
STIX ID: report--5568b4ea-4485-5629-b2a3-41eb86c3797b
Feed Name: HackRead
Check Point Research uncovered a large network of highly realistic fake download websites impersonating legitimate tools (e.g., Ghidra, dnSpy) that funnel users through CloudFront-hosted JavaScript and a Traffic Distribution System to deliver malware. The operation, active since mid-2025 with broad global reach, distributes multiple threats — notably RemusStealer (Go-based infostealer exfiltrating browser credentials and wallets), AnimateClipper (clipboard hijacker via complex script chains), and SessionGate (obfuscated multi-stage loader) — using sophisticated gating and detection-evasion techniques; several C2 domains and indicators are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
