logo

GitHub, GitLab Abused for Malware and Phishing Campaigns

ID: e7fc22b0-c06b-57d6-859d-573d63c0b8b1

STIX ID: report--e7fc22b0-c06b-57d6-859d-573d63c0b8b1

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Attackers are increasingly abusing trusted Git repository platforms (primarily GitHub, also GitLab) to host malware and credential-phishing sites that bypass traditional perimeter controls. The report details that ~95% of abuses use GitHub, with 2025 accounting for ~45% of observed campaigns, and describes delivery methods (raw content URLs, github.io/gitlab.io pages), hybrid chains combining RATs and phishing, common malware families (Remcos, Byakugan, Async RAT, DcRAT), and evasion techniques such as password-protected archives and anti-automation gates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.