GitHub Repos Targeted in Cyber-Extortion Attacks
ID: 34a3f3fc-bf72-5284-9e04-866f0e42ebca
STIX ID: report--34a3f3fc-bf72-5284-9e04-866f0e42ebca
Feed Name: Dark Reading
An extortion campaign attributed to an actor calling itself "Gitloker" is exploiting GitHub's commenting/notification features to send phishing emails appearing from [email protected] and to trick victims into authorizing OAuth apps, resulting in repository deletion, data theft, and ransom demands. Multiple users have reported compromises since at least February 2024; observed infrastructure includes the domains githubcareers.online and githubtalentcommunity.online, and GitHub advises reviewing sessions, personal access tokens, OAuth app authorizations, passwords, and two-factor recovery codes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
