logo

Microsoft admits GitHub hosted malware that infected almost a million devices

ID: 159168fa-7d8a-514a-aed4-a763cbc2d9e7

STIX ID: report--159168fa-7d8a-514a-aed4-a763cbc2d9e7

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-03-10

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Microsoft reported a malvertising campaign that used multiple redirect layers and a GitHub-hosted dropper to install multi-stage payloads—first-stage reconnaissance, then varied third-stage modules performing command-and-control, data exfiltration and credential theft—potentially exposing nearly one million devices; the roundup also calls out several actively exploited high-severity CVEs, Cisco advisories, privacy-harming phone-cleaner apps, AI-based phishing impersonations, and legislative and enforcement developments addressing scams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.