Hackers Exploit Snap Domains to Inject Malicious Code into Linux Software Packages
ID: b7331877-11e6-5410-aef1-b862b271e5ee
STIX ID: report--b7331877-11e6-5410-aef1-b862b271e5ee
Feed Name: GBHackers
A campaign is actively hijacking Snap Store publisher accounts by registering expired publisher domains, using password resets to take over established publisher accounts and push malicious revisions that act as cryptocurrency wallet stealers; the malware harvests recovery phrases and exfiltrates them (via Telegram bots), employing obfuscation (homoglyphs) and bait-and-switch publication techniques. The report documents C2 artefacts, sample Telegram identifiers, and recommends mitigations including domain expiry monitoring, mandatory 2FA, and stricter verification for account recovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
