'Stargazer Goblin' Amasses Rogue GitHub Accounts to Spread Malware
ID: 707e46a7-65c3-5125-ae05-43709337f1d7
STIX ID: report--707e46a7-65c3-5125-ae05-43709337f1d7
Feed Name: Dark Reading
Researchers uncovered a criminal operation dubbed the Stargazers Ghost Network in which the threat actor "Stargazer Goblin" uses over 3,000 inauthentic GitHub accounts to star, fork, and watch malicious repositories to make them appear legitimate. The actor operates a malware distribution-as-a-service (DaaS), advertising on underground forums and distributing multiple stealer families (e.g., Atlantida, Rhadamanthys, Redline, Lumma) and other malware, and likely extends this influence network across platforms like Twitter, YouTube, Discord, and more to amplify credibility and lure victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
