Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers
ID: 33291195-fd17-5b72-aef4-b8ecd8bba344
STIX ID: report--33291195-fd17-5b72-aef4-b8ecd8bba344
Feed Name: cybersecurityNews.com
A targeted Slack-based social engineering campaign impersonated a Linux Foundation leader to send a Google Sites phishing link that harvested credentials and tricked victims into installing a malicious root certificate; that certificate enabled TLS interception and facilitated delivery of platform-specific malware (macOS binary 'gapi' communicating with 2.26.97.61). The report includes IoCs (phishing URL, fake email, access key, C2 IP, binary name) and remediation recommendations: verify identities out of band, never install root certificates from chat links, and enable MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
