'GoIssue' Cybercrime Tool Targets GitHub Developers En Masse
ID: ab4609e4-b6b8-5d63-943c-6961dc1e34fd
STIX ID: report--ab4609e4-b6b8-5d63-943c-6961dc1e34fd
Feed Name: Dark Reading
Date Published: 2024-11-12
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers discovered GoIssue, a commercial tool sold on cybercrime forums that automates harvesting email addresses and using GitHub tokens to target developers, enabling bulk phishing, credential theft, and subsequent malicious activity (including OAuth-based account takeover and supply-chain attacks). The tool is marketed to attackers and may be linked to the Gitloker repository-extortion campaign, representing a scalable threat to GitHub users and organizations with developer-centric exposures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
