GitHub Impersonation Deploys Information Stealer
ID: added522-3bf9-5715-a31e-377e78f6e91c
STIX ID: report--added522-3bf9-5715-a31e-377e78f6e91c
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf identified and removed a malicious GitHub impersonation campaign that hosted fake vendor repositories (including an Arctic Wolf impersonator) linking to ZIP downloads which contained a trojanized executable that side-loaded a malicious libcurl.dll to deploy the BoryptGrab information-stealer; investigators found nearly 300 similar repositories impersonating multiple security vendors and have published IOCs and enhanced detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
