logo

'Stargazer Goblin' Amasses Rogue GitHub Accounts to Spread Malware

ID: 707e46a7-65c3-5125-ae05-43709337f1d7

STIX ID: report--707e46a7-65c3-5125-ae05-43709337f1d7

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-24

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers uncovered a criminal operation dubbed the Stargazers Ghost Network in which the threat actor "Stargazer Goblin" uses over 3,000 inauthentic GitHub accounts to star, fork, and watch malicious repositories to make them appear legitimate. The actor operates a malware distribution-as-a-service (DaaS), advertising on underground forums and distributing multiple stealer families (e.g., Atlantida, Rhadamanthys, Redline, Lumma) and other malware, and likely extends this influence network across platforms like Twitter, YouTube, Discord, and more to amplify credibility and lure victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.