GitVenom campaign targets gamers and crypto investors by posing as fake GitHub projects
ID: e0651169-8667-5347-8892-b186c5b9daf5
STIX ID: report--e0651169-8667-5347-8892-b186c5b9daf5
Feed Name: Security Affairs
Kaspersky researchers uncovered the GitVenom campaign where operators published hundreds of fake GitHub projects (using AI-generated READMEs, fake commits, tags and frequent timestamp updates) to trick users into running malicious code. The repositories across multiple languages delivered a downloader that fetched additional payloads from an attacker-controlled GitHub repo, installing a Node.js stealer, AsyncRAT/Quasar backdoors, and a clipboard hijacker used to steal cryptocurrency (approximately 5 BTC observed); infections were concentrated in Russia, Brazil and Turkey.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
