GitHub, GitLab Abused for Malware and Phishing Campaigns
ID: e7fc22b0-c06b-57d6-859d-573d63c0b8b1
STIX ID: report--e7fc22b0-c06b-57d6-859d-573d63c0b8b1
Feed Name: GBHackers
Attackers are increasingly abusing trusted Git repository platforms (primarily GitHub, also GitLab) to host malware and credential-phishing sites that bypass traditional perimeter controls. The report details that ~95% of abuses use GitHub, with 2025 accounting for ~45% of observed campaigns, and describes delivery methods (raw content URLs, github.io/gitlab.io pages), hybrid chains combining RATs and phishing, common malware families (Remcos, Byakugan, Async RAT, DcRAT), and evasion techniques such as password-protected archives and anti-automation gates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
