21 votes

A hacker ‘ghost’ network is quietly spreading malware on GitHub

4 comments

  1. skybrian
    Link
    From the article: …

    From the article:

    The Stargazers Ghost Network, which Check Point named after one of the first accounts they spotted, has been spreading malicious GitHub repositories that offer downloads of social media, gaming, and cryptocurrency tools. For instance, pages might be claiming to provide code to run a VPN or license a version of Adobe's Photoshop. These are mostly targeting Windows users, the research says, and aim to capitalize on people potentially searching for free software online.

    The operator behind the network charges other hackers to use their services, which Check Point call “distribution as a service.” The harmful network has been spotted sharing various types of ransomware and info-stealer malware, Check Point says, including the Atlantida Stealer, Rhadamanthys, and the Lumma Stealer. Terefos says he discovered the network while researching instances of the Atlantida Stealer. The researcher says the network could be bigger than he expects, as he has also seen legitimate GitHub accounts being taken over using stolen login details.

    “We disabled user accounts in accordance with GitHub’s Acceptable Use Policies, which prohibit posting content that directly supports unlawful active attack or malware campaigns that are causing technical harms,” says Alexis Wales, vice president of security operations at GitHub. “We have teams dedicated to detecting, analyzing, and removing content and accounts that violate these policies.”

    The Stargazer Goblin threat actor identified by Check Point sells their services through ads on cybercrime forums and also through a Telegram account. A posts on a Russian-language cybercrime forum advertises 100 stars for $10 and 500 for $50 and says they can provide clones of existing repositories and trusted accounts. “For GitHub, the process looks organic,” one translated post says. The Check Point research says the network could have started operating as early as August 2022 and may have made as much as $100,000—from mid-May to mid-June this year, they estimate the operator made around $8,000.

    8 votes
  2. [3]
    cfabbro
    Link
    Mirror: https://archive.is/DwbmN (was originally submitted as the topic link, but Tildes policy is to submit original sources, even paywalled ones)

    Mirror: https://archive.is/DwbmN
    (was originally submitted as the topic link, but Tildes policy is to submit original sources, even paywalled ones)

    4 votes
    1. [2]
      skybrian
      Link Parent
      Oops! Pasted the wrong link. Thanks!

      Oops! Pasted the wrong link. Thanks!

      2 votes
      1. cfabbro
        Link Parent
        NP. I've done that a few times over the years, myself. :P

        NP. I've done that a few times over the years, myself. :P

        3 votes