OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures
ID: 3c9fc367-880f-5812-8dc6-ed8580fa1924
STIX ID: report--3c9fc367-880f-5812-8dc6-ed8580fa1924
Feed Name: HackRead
**OpenSSF warns of a targeted Slack phishing campaign** that impersonates community leaders to lure developers to a fake Google Workspace flow; victims are asked to provide credentials and install a malicious root certificate that enables encrypted-traffic interception, and macOS users may be served a 'gapi' payload capable of full system takeover. The campaign targeted the TODO Group Slack workspace, used a now-deleted Sites link and fake identifiers, and resembles prior developer-targeting operations reportedly linked to North Korean state-sponsored actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
