logo

New Infostealer Campaign Abuses GitHub Releases For Payload Hosting

ID: 59a94fe9-da67-5d78-b02a-e14bbeda548e

STIX ID: report--59a94fe9-da67-5d78-b02a-e14bbeda548e

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: Varshini

...
...

This report from Cyble CRIL describes a targeted infostealer campaign that delivers an in-memory PowerShell payload via a malicious LNK in a RAR archive, hosts components on GitHub Releases, and deploys a Python-based implant named "WindowsHelper" to stealthily harvest credentials, cookies, Telegram session data, keystrokes, screenshots, and install remote access tools for persistent surveillance and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.