logo

Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers

ID: 33291195-fd17-5b72-aef4-b8ecd8bba344

STIX ID: report--33291195-fd17-5b72-aef4-b8ecd8bba344

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A targeted Slack-based social engineering campaign impersonated a Linux Foundation leader to send a Google Sites phishing link that harvested credentials and tricked victims into installing a malicious root certificate; that certificate enabled TLS interception and facilitated delivery of platform-specific malware (macOS binary 'gapi' communicating with 2.26.97.61). The report includes IoCs (phishing URL, fake email, access key, C2 IP, binary name) and remediation recommendations: verify identities out of band, never install root certificates from chat links, and enable MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.