Attackers Hijacking Official GitHub Desktop Repository to Distribute Malware as Official Installer
ID: 5dbca68f-1591-568b-84eb-be1af31857c3
STIX ID: report--5dbca68f-1591-568b-84eb-be1af31857c3
Feed Name: cybersecurityNews.com
Threat Score
Cybercriminals used repo squatting and sponsored ads to distribute a malicious Windows installer (e.g., GitHubDesktopSetup-x64.exe) that impersonates GitHub Desktop and other apps; the loader conceals a .NET payload in the file overlay and leverages OpenCL GPU checks (GPUGate) and code misdirection to evade sandbox/VM analysis, with infections observed primarily in Europe and the EEA and later spreading to Japan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
