logo

GitCaught campaign relies on Github and Filezilla to deliver multiple malware

ID: bee863ce-e80b-5d4f-9614-f8546dc92b0b

STIX ID: report--bee863ce-e80b-5d4f-9614-f8546dc92b0b

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2024-05-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Recorded Future’s Insikt Group uncovered the "GitCaught" campaign in which Russian-speaking cybercriminals impersonated legitimate macOS applications and used a GitHub profile plus file-sharing/FileZilla infrastructure to distribute multiple malware families (Atomic macOS Stealer, Lumma, Octo, Vidar); the campaign shares C2 infrastructure, abused trusted platforms to evade detection, and Recorded Future identified numerous malicious domains, repositories, additional IPs, and published IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.