Check Point Research a click hijacking/TDS campaign spoofing security tools like Ghidra and dnSpy. Delivers Remus and other infostealers.
Actions
Refer to IOC table at the bottom of the CHeck Point post for stealers/C2 domains/hashes. Not listed in that table, however, are the initial access domains.
Value
Type
Description
d33f51dyacx7bd.cloudfront[.]net
Domain
Malicious JS fetch
ghidralite[.]com
Domain
Ghidra spoof
dnspy[.]org
Domain
Tool spoof
ilspy[.]org
Domain
Tool spoof
grpcurl[.]com
Domain
Tool spoof
mqttexplorer[.]com
Domain
Tool spoof
mfcmapi[.]com
Domain
Tool spoof
winsetupfromusb[.]org
Domain
Tool spoof
crystaldiskmark[.]org
Domain
Tool spoof
guiformat[.]com
Domain
Tool spoof
oundhertobeconsist[.]org
Domain
Redirector
Notes
Renée Burton had some additional research on LinkedIn.
Here’s the historic (Nov 2025) report, referenced in the Checkpoint Research report. There are several domains that were examined in the initial report: