logo

New Infostealer Campaign Uses GitHub Releases for Payload Hosting and Evasion

ID: e2701ba1-e665-5b83-9ea4-cde84c3882bd

STIX ID: report--e2701ba1-e665-5b83-9ea4-cde84c3882bd

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

HumanitarianBait is an active phishing campaign that uses a RAR-attached LNK dropper and GitHub Releases to deliver a PyArmor-obfuscated Python implant that steals browser passwords, cookies, keystrokes, clipboard contents, screenshots, Telegram data and files, and can install remote access tools (RustDesk/AnyDesk). The campaign employs in-memory PowerShell execution, anti-sandbox techniques, user-space persistence (AppData "WindowsHelper", VBScript launchers, scheduled tasks), and hosts payloads in GitHub Releases to evade automated scanning; IoCs including SHA-256 hashes, URLs, and a C2 IP are provided alongside mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.