Alert: Social Engineering Campaign Targets Open Source Developers via Slack
ID: 66cf5675-c429-57ef-8c2c-78581d7bc338
STIX ID: report--66cf5675-c429-57ef-8c2c-78581d7bc338
Feed Name: securityonline.info
A high-severity social engineering campaign is targeting open-source developers via Slack impersonation, luring victims to a fraudulent Google Sites link that harvests credentials and prompts installation of a malicious root certificate. On macOS the campaign downloads and executes a binary named 'gapi' from IP 2.26.97.61; on Windows users are prompted to install the fake certificate, enabling encrypted-traffic interception, credential theft, and potential full system compromise. The advisory urges verification of identities, scrutiny of links, rejection of unsolicited root-certificate installs, immediate containment steps (disconnect, remove certificates, rotate credentials) and reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
