logo

GitHub Comments from Legitimate Repositories Exploited to Deliver Remcos RAT

ID: a976b53e-d336-57e7-897b-dfdcbc487726

STIX ID: report--a976b53e-d336-57e7-897b-dfdcbc487726

Feed Name: Netskope Threat Labs

Threat Score
70/100

Date Published: 2024-10-21

Date Updated: 2026-04-28

Author: Paolo Passeri

...
...

Netskope highlights a Cofense-discovered campaign targeting insurance and finance organizations that abused trusted GitHub repositories and GitHub comments to distribute the Remcos RAT. The report emphasizes the technique of embedding malicious payloads in repository comments to leverage trust in reputable organizations and describes Netskope mitigations — adaptive access control, cloud instance detection, threat protection (AV, ML, sandboxing), Cloud Exchange integrations, and advanced analytics — to detect and block such delivery mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.