Watch out, security researchers! If you search for "Ghidra download," you may be sent to a spoofing site that will gift you an infostealer instead of a disassembler. Multiple tools have spoof sites like this.
https://discourse.ifin.network/t/tds-clickjacking-campaign-lures-with-security-tools/544

TDS/Clickjacking Campaign Lures with Security Tools
Last Updated: 2026-06-04T21:40:11Z (UTC) What’s Happening Check Point Research a click hijacking/TDS campaign spoofing security tools like Ghidra and dnSpy. Delivers Remus and other infostealers. Actions Refer to IOC table at the bottom of the CHeck Point post for stealers/C2 domains/hashes. Not listed in that table, however, are the initial access domains. Value Type Description d33f51dyacx7bd.cloudfront[.]net Domain Malicious JS fetch ghidralite[.]com Domain Ghidra spoof dnspy...






