logo

RU-APT-ChainReaver-L Hijacks Trusted Sites and GitHub in Sweeping Cross-Platform Supply Chain Attack

ID: f5c2cace-a0b6-551e-8376-451a77fe25cc

STIX ID: report--f5c2cace-a0b6-551e-8376-451a77fe25cc

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A newly exposed APT campaign dubbed RU-APT-ChainReaver-L hijacks popular mirror/file-distribution sites and compromised GitHub accounts to funnel Windows, macOS, and iOS users to attacker-controlled infrastructure; payloads include powerful infostealers and trojanized apps, often delivered via malicious redirects, fake installers, one-line Terminal commands, and forged code-signed binaries. The operation uses hundreds of rotating domains and legitimate platforms (GitHub, Google Sites, Dropbox, MediaFire, etc.) to blend into normal traffic, complicating detection; researchers recommend XDR, strict file-transfer monitoring, isolation of untrusted downloads, and targeted user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.