Huge hacking campaign uses spoofed Ghidra, dnSpy, and SpiderFoot security tools to harvest ad revenue and serve malware | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker



  • Over 100 spoofed sites mimic trusted security tools
  • Campaign serves SessionGate, RemusStealer, AnimateClipper
  • Primary goal appears to be traffic monetization

A large-scale malicious campaign was recently uncovered, spoofing reputable open-source security tools to harvest ad revenue and serve malware to developers and security researchers.

Security outfit Check Point Research (CPR) recently published an in-depth report, detailing the campaign. Apparently, threat actors created more than 100 websites spoofing tools such as Ghidra, dnSpy, and SpiderFoot. Visitors were routed through a Traffic Distribution System (TDS) and served multiple malware variants, including SessionGate, RemusStealer, and AnimateClipper.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW