TDS/Clickjacking Campaign Lures with Security Tools

Last Updated: 2026-06-04T21:40:11Z

What’s Happening

Check Point Research a click hijacking/TDS campaign spoofing security tools like Ghidra and dnSpy. Delivers Remus and other infostealers.

Actions

Refer to IOC table at the bottom of the CHeck Point post for stealers/C2 domains/hashes. Not listed in that table, however, are the initial access domains.

Value Type Description
d33f51dyacx7bd.cloudfront[.]net Domain Malicious JS fetch
ghidralite[.]com Domain Ghidra spoof
dnspy[.]org Domain Tool spoof
ilspy[.]org Domain Tool spoof
grpcurl[.]com Domain Tool spoof
mqttexplorer[.]com Domain Tool spoof
mfcmapi[.]com Domain Tool spoof
winsetupfromusb[.]org Domain Tool spoof
crystaldiskmark[.]org Domain Tool spoof
guiformat[.]com Domain Tool spoof
oundhertobeconsist[.]org Domain Redirector

Notes

Renée Burton had some additional research on LinkedIn.

Here’s the historic (Nov 2025) report, referenced in the Checkpoint Research report. There are several domains that were examined in the initial report:

  • ghidralite[.]com

  • deepseekweb[.]io

  • geckodriver[.]org

  • getimagemagick[.]com

  • getsharex[.]org

  • helixeditor[.]com

  • mtkdriver[.]org

  • radminvpn[.]org

  • superputty[.]org

  • vncviewer[.]org

  • winra1n[.]org

libgpiod_mx_pivot.csv (87.5 KB)

having been pointed to the libgpiod fake domain, was able to enumerate 39 more thanks to a shared mailserver.

More than one possesses “not affiliated with…” disclaimer at the bottom, so am guessing it’s the same scumbags.

The MISP event has been updated with the new domains. Thanks Ian!