GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure
ID: 78507cd9-74ef-5b51-9a89-0627e35d1630
STIX ID: report--78507cd9-74ef-5b51-9a89-0627e35d1630
Feed Name: Recorded Future Blog
Recorded Future's Insikt Group uncovered a coordinated cybercriminal campaign in which Russian-speaking actors abused GitHub to host counterfeit installers of legitimate macOS apps (e.g., 1Password, Bartender 5, Pixelmator Pro) to distribute multiple info-stealer malware families (Atomic macOS Stealer/AMOS, Vidar, Lumma, Octo). Analysis revealed a shared command-and-control infrastructure suggesting organized operations; the report warns that trusted developer platforms are being weaponized and recommends organization-wide code review, automated scanning tools, and enhanced monitoring of unauthorized applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
