logo

Over 3,000 GitHub accounts used by malware distribution service

ID: 30bbf26e-426c-5a06-a5db-74790ec291b4

STIX ID: report--30bbf26e-426c-5a06-a5db-74790ec291b4

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-24

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

The report describes a large-scale DaaS operation named the 'Stargazers Ghost Network' run by 'Stargazer Goblin', which uses thousands of fake GitHub accounts and compromised WordPress sites to distribute password-protected archives containing info-stealers (e.g., RedLine, Lumma, Atlantida). Check Point observed operational roles for ghost accounts, phishing templates targeting niche audiences, an attack chain using HTA and PowerShell to deploy stealers, ongoing active repositories despite takedowns, and estimated monetization exceeding $100,000.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.