New Gitloker attacks wipe GitHub repos in extortion scheme
ID: 5557c615-45e3-5fc4-aff6-516614c254db
STIX ID: report--5557c615-45e3-5fc4-aff6-516614c254db
Feed Name: Bleeping Computer
Threat Score
Attackers operating under the Telegram handle "Gitloker" are actively compromising GitHub accounts—apparently using stolen credentials—wiping repository contents, and leaving a README claiming they backed up victims' data and instructing victims to contact them on Telegram for recovery/extortion. The campaign has impacted dozens of repositories; the report also recalls prior GitHub breaches and advises users to enable MFA, review keys/apps, and monitor account activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
