New Infostealer Campaign Uses GitHub Releases for Payload Hosting and Evasion
ID: e2701ba1-e665-5b83-9ea4-cde84c3882bd
STIX ID: report--e2701ba1-e665-5b83-9ea4-cde84c3882bd
Feed Name: cybersecurityNews.com
HumanitarianBait is an active phishing campaign that uses a RAR-attached LNK dropper and GitHub Releases to deliver a PyArmor-obfuscated Python implant that steals browser passwords, cookies, keystrokes, clipboard contents, screenshots, Telegram data and files, and can install remote access tools (RustDesk/AnyDesk). The campaign employs in-memory PowerShell execution, anti-sandbox techniques, user-space persistence (AppData "WindowsHelper", VBScript launchers, scheduled tasks), and hosts payloads in GitHub Releases to evade automated scanning; IoCs including SHA-256 hashes, URLs, and a C2 IP are provided alongside mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
