logo

RU-APT-ChainReaver-L Hijacks Trusted Websites and GitHub Repos in Massive Cross-Platform Supply Chain Campaign

ID: c37d2d46-743e-5460-8d85-79ed8dcc97a1

STIX ID: report--c37d2d46-743e-5460-8d85-79ed8dcc97a1

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The RU-APT-ChainReaver-L campaign is a sophisticated supply-chain operation that has compromised major mirror file-sharing services (Mirrored.to, Mirrorace.org) and numerous GitHub accounts to deliver signed infostealer malware across Windows, macOS (MacSync Stealer), and iOS. Researchers observed deceptive redirect chains, valid code signing certificates, password-protected archives on cloud storage, and a threat infrastructure of over 100 domains tied to widespread credential theft; recommendations include user education, EDR, network monitoring for file-sharing services and new domains, and routing downloads through analysis platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.