logo

Flying Under the Radar: Abusing GitHub for Malicious Infrastructure

ID: 0f107d6a-a67a-58b5-893a-98affb6be20b

STIX ID: report--0f107d6a-a67a-58b5-893a-98affb6be20b

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2024-01-11

Date Updated: 2026-04-28

...
...

Recorded Future Insikt Group research describes how cybercriminals and APTs increasingly abuse GitHub and other legitimate code-hosting services for payload delivery, dead-drop resolving, full C2, exfiltration, phishing, and repository poisoning — a trend termed "living-off-trusted-sites" (LOTS). The report notes observed samples (March–November 2023), recommends short-term blocking/flagging of known-abused GitHub services, and urges longer-term investment in visibility, diverse detection approaches, and platform-level mitigations from legitimate internet services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.