Stargazers Ghost Network


Recently, Check Point Research observed threat actors using GitHub to achieve initial infections by utilizing new methods.

Previously, GitHub was used to distribute malicious software directly, with a malicious script downloading either raw encrypted scripting code or malicious executables. Their tactics have now changed and evolved. Threat actors now operate a network of “Ghost” accounts that distribute malware via malicious links on their repositories and encrypted archives as releases. This network not only distributes malware but also provides various other activities that make these “Ghost” accounts appear as normal users.

Read more…
Source: Check Point


Sign up for our Newsletter


Related:

  • Ransomware Redefined: RedEnergy Stealer-as-a-Ransomware attacks

    June 21, 2023

    Zscaler ThreatLabz has discovered a new malware variant, RedEnergy stealer (not to be confused with the australian company Red Energy) that fits into the hybrid Stealer-as-a-Ransomware threat category. RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive ...

  • Ghana’s EOCO collaborates with Nigeria’s EFCC in cybercrime fight

    June 21, 2023

    Ghana’s Economic and Organised Crime Office (EOCO) is fostering close collaboration with the Economic and Financial Crimes Commission (EFCC) of Nigeria in the fight against cybercrime. Combining survey results from INTERPOL showed an increase of 132 per cent in reported cybercrime between 2013 and 2015, with an average of USD2.7 million from businesses and USD422, 000 ...

  • Hackers threaten to leak 80GB of confidential data stolen from Reddit

    June 19, 2023

    Hackers are threatening to release confidential data stolen from Reddit unless the company pays a ransom demand – and reverses its controversial API price hikes. In a post on its dark web leak site, the BlackCat ransomware gang, also known as ALPHV, claims to have stolen 80 gigabytes of compressed data from Reddit during a February ...

  • Microsoft Azure and Outlook outages were caused by DDoS attacks

    June 19, 2023

    Microsoft has confirmed that outages to its Azure and Outlook services were caused by DDoS attacks, which the company puts down to the threat actor that it tracks as Storm-1359. This follows the tech giant’s new nomenclature for threats, whereby Storm denotes a group that is in development. Otherwise known as Anonymous Sudan, it is said ...

  • Decade Old DDoS-for-Hire Service Taken Down, Administrators Arrested

    June 19, 2023

    Polish authorities took down a DDoS-for-hire service that’s been around for a decade following an investigation with support of the FBI, Europol and law enforcement agencies from Germany, Belgium and the Netherlands. DDoS attacks are always a nuisance, but they can inflict serious damage to companies and organizations. The simple fact that a webpage or a ...

  • Military leaders warn U.S. must prepare for cyber, infrastructure threat

    June 16, 2023

    The United States must immediately get ready for domestic, cyber-enabled attacks on critical domestic infrastructure and guard against foreign-initiated information operations targeted at the American people, according to speakers and panelists at an Association of the U.S. Army symposium on Wednesday in Arlington, Virginia. Mark Bristow, director of the Cyber Infrastructure Protection Innovation Center (CIPIC) at ...