Inside the AI-Driven “Lure Factory” Flooding GitHub with Trojans
ID: fe8577b2-25ee-5bfd-8ee1-323ead6bf667
STIX ID: report--fe8577b2-25ee-5bfd-8ee1-323ead6bf667
Feed Name: securityonline.info
### Executive Summary Netskope Threat Labs uncovered "TroyDen’s Lure Factory," a sophisticated, AI-assisted campaign that has trojanized over 300 GitHub repositories to deliver credential-stealing malware. The operation uses convincing lures, a two-component payload (renamed LuaJIT runtime and encrypted Lua script), advanced sandbox-evasion (including an extremely long sleep), rapid screenshot exfiltration to Frankfurt-based infrastructure, and DPAPI decryption to harvest credentials, likely dropping info-stealers such as Redline or LummaStealer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
