Malicious Visual Studio projects on GitHub push Keyzetsu malware
ID: ec5914d9-05f5-5fb8-ba95-35e620423fd9
STIX ID: report--ec5914d9-05f5-5fb8-ba95-35e620423fd9
Feed Name: Bleeping Computer
Threat actors are abusing GitHub automation and malicious Visual Studio project files to distribute a variant of the Keyzetsu clipboard-hijacker that replaces copied cryptocurrency addresses. The campaign boosts repository visibility using GitHub Actions and fake stars, hides payload execution in PreBuildEvent scripts that run batch and base64 PowerShell stagers, delivers an encrypted/7z payload padded to ~750MB to evade scanners, and creates a scheduled task (Feedback_API_VS_Services_Client) for persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
