RU-APT-ChainReaver-L Hijacks Trusted Websites and GitHub Repos in Massive Cross-Platform Supply Chain Campaign
ID: c37d2d46-743e-5460-8d85-79ed8dcc97a1
STIX ID: report--c37d2d46-743e-5460-8d85-79ed8dcc97a1
Feed Name: cybersecurityNews.com
The RU-APT-ChainReaver-L campaign is a sophisticated supply-chain operation that has compromised major mirror file-sharing services (Mirrored.to, Mirrorace.org) and numerous GitHub accounts to deliver signed infostealer malware across Windows, macOS (MacSync Stealer), and iOS. Researchers observed deceptive redirect chains, valid code signing certificates, password-protected archives on cloud storage, and a threat infrastructure of over 100 domains tied to widespread credential theft; recommendations include user education, EDR, network monitoring for file-sharing services and new domains, and routing downloads through analysis platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
