One Million Devices Infected: Hackers Use Malvertising and GitHub to Spread Infostealers
ID: 87b82353-95f8-5d62-be6c-41871d4bf102
STIX ID: report--87b82353-95f8-5d62-be6c-41871d4bf102
Feed Name: infostealers.com
Microsoft Threat Intelligence observed a widespread malvertising campaign (Storm-0408) beginning in December 2024 that used malicious iframe redirectors on illegal streaming sites to funnel victims to payloads hosted on GitHub (and occasionally Discord/Dropbox). The multi-stage attack deployed signed droppers that fetched second-stage system discovery components which exfiltrated Base64-encoded system/browser data, then deployed third- and fourth-stage components — including Lumma/Doenerium information stealers, NetSupport RAT, AutoIT loaders, and obfuscated PowerShell — to achieve persistence, disable defenses, and exfiltrate credentials and documents; the report provides extensive IOCs, detections, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
