Polygon Powered: Vietnamese Operator Deploys 16 Generations of LuaJIT Malware via GitHub
ID: 6ea3c23d-2e92-554c-977f-a482b4aad915
STIX ID: report--6ea3c23d-2e92-554c-977f-a482b4aad915
Feed Name: securityonline.info
Researchers uncovered a year-long, large-scale campaign (active since Mar 2025) that uses 600+ malicious ZIP archives across dozens of GitHub accounts to distribute a multi-stage LuaJIT loader which resolves C2 via a Polygon smart contract and ultimately deploys the StealC information stealer; observed capabilities include credential harvesting, session hijacking, targeted reconnaissance, and optional module delivery, with infrastructure concentrated on bulletproof hosting and evidence pointing to a Vietnamese-speaking operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
