Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware

https://hackread.com/wp-content/uploads/2026/06/Fake-Website-Network-Spreading-RemusStealer-AnimateClipper-and-SessionGate-Malware-3.png

A network of fake websites is trapping unsuspecting users by claiming to be official download pages for free tools like Ghidra, dnSpy, ILSpy, and CrystalDiskMark. Discovered by Check Point Research, this operation uses highly realistic portals to trick visitors into downloading malware instead of legitimate software.

How the Scam Works

Usually, when open-source projects are searched on Google, users trust the first link that appears. In this campaign, hackers exploit exactly this habit. Researchers explain in the blog post that they have developed 100+ clone websites that mimic real portals, even preserving authentic GitHub links when users hover over download buttons.

But clicking the button triggers CloudFront-hosted JavaScript, which redirects users to a Traffic Distribution System (TDS). It employs strict gating, analysing the visitor’s country, browser fingerprint, and VPN usage.

Discover more

Malware removal service

Hacking & Cracking

Affiliate product reviews

If it suspects a security investigator, a reproducibility...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more