GitCaught campaign relies on Github and Filezilla to deliver multiple malware
ID: bee863ce-e80b-5d4f-9614-f8546dc92b0b
STIX ID: report--bee863ce-e80b-5d4f-9614-f8546dc92b0b
Feed Name: Security Affairs
Recorded Future’s Insikt Group uncovered the "GitCaught" campaign in which Russian-speaking cybercriminals impersonated legitimate macOS applications and used a GitHub profile plus file-sharing/FileZilla infrastructure to distribute multiple malware families (Atomic macOS Stealer, Lumma, Octo, Vidar); the campaign shares C2 infrastructure, abused trusted platforms to evade detection, and Recorded Future identified numerous malicious domains, repositories, additional IPs, and published IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
