New GitHub Scam Uses Fake “Mods” and “Cracks” to Steal User Data
ID: 9086ccbf-f887-5772-98db-b52632b595d4
STIX ID: report--9086ccbf-f887-5772-98db-b52632b595d4
Feed Name: GBHackers
A research analysis uncovers a widespread campaign using over 1,100 GitHub repositories that masquerade as game modifications and cracked software to distribute the Python-based Redox stealer, which automates credential and cryptocurrency-wallet extraction and exfiltration (via obfuscated Discord webhooks). The report documents social-engineering tactics (topic poisoning, AI-generated READMEs), payload obfuscation (passworded RARs, Anonfiles), technical harvesting modules (browser/Steam/Discord/SQLite scraping, DPAPI-based secrets), active evasion of GitHub detection, and an estimated scale of thousands of victims monthly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
