Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware
A network of fake websites is trapping unsuspecting users by claiming to be official download pages for free tools like Ghidra, dnSpy, ILSpy, and CrystalDiskMark. Discovered by Check Point Research, this operation uses highly realistic portals to trick visitors into downloading malware instead of legitimate software.
How the Scam Works
Usually, when open-source projects are searched on Google, users trust the first link that appears. In this campaign, hackers exploit exactly this habit. Researchers explain in the blog post that they have developed 100+ clone websites that mimic real portals, even preserving authentic GitHub links when users hover over download buttons.
But clicking the button triggers CloudFront-hosted JavaScript, which redirects users to a Traffic Distribution System (TDS). It employs strict gating, analysing the visitor’s country, browser fingerprint, and VPN usage.
Discover more
Malware removal service
Hacking & Cracking
Affiliate product reviews
If it suspects a security investigator, a reproducibility...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE