Giantspider.7z May 2026

Distribution through a lookalike website, 7zip[.]com (impersonating the legitimate 7-zip.org ).

The archive typically contains a modified 7zfm.exe that drops several hidden Go-compiled binaries: GiantSpider.7z

7zip[.]com (Note: The official site is 7-zip.org ). Distribution through a lookalike website, 7zip[

The primary proxy payload that establishes connections to C2 servers. A support library used by the main payload. Malicious Actions Distribution through a lookalike website

Collects system data including CPU details, hardware configuration, and network info. Technical Indicators

Installs as a SYSTEM-level Windows service to ensure it runs even after reboots.

The installers were signed with a now-revoked certificate issued to JOZEAL NETWORK TECHNOLOGY CO., LIMITED to bypass basic security warnings. Execution & Payload Details