logo

Uncovering Compromised Git Admins: How to Detect actors like theCom

ID: d6be4614-9a2f-52d8-9460-ef14dffd3905

STIX ID: report--d6be4614-9a2f-52d8-9460-ef14dffd3905

Feed Name: Abstract Security Blog

Threat Score
70/100

Date Published: 2025-06-11

Date Updated: 2026-04-26

...
...

**Executive Summary:** This report describes operations by theCom, an opportunistic threat actor group that targets IT helpdesk and administrative GitHub/GitLab accounts via social engineering to obtain persistent access (personal access tokens, added collaborators), disable protections (MFA/SAML), and exfiltrate repositories or credentials to pivot into cloud and infrastructure; it provides detection signals from GitHub audit logs, recommended mitigations (admin approval of PATs, restrict classic tokens, enforce MFA/SAML), and ASTRO detection rules to find suspicious activity such as mass repository retrieval and configuration changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.