Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank
ID: 2998a99d-c051-50c0-a2cc-5356129594c8
STIX ID: report--2998a99d-c051-50c0-a2cc-5356129594c8
Feed Name: The Register (Security)
Infosec researchers uncovered the "Stargazer Ghost Network," a coordinated campaign of over 3,000 malicious GitHub accounts operated by a group dubbed "Stargazer Goblin," which used non-email phishing (Discord and similar platforms) and a multi-account GitHub infrastructure to host deceptive repositories that delivered malware (including Atlantida stealer and Rhadamanthys). The network used a three-account chain (phishing template, image host, password-protected release serving malware), leveraged automation and possibly generative AI to appear legitimate, and achieved thousands of downloads/infections before GitHub disabled implicated accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
