logo

Threat actor Banana Squad exploits GitHub repos in new campaign

ID: 6d86deba-7a45-5b27-b823-12a04bdc5784

STIX ID: report--6d86deba-7a45-5b27-b823-12a04bdc5784

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-06-18

Date Updated: 2026-04-29

Author: [email protected] (Robert Simmons)

...
...

ReversingLabs researchers uncovered a campaign by Banana Squad that trojanized at least 67 GitHub repositories by uploading Python projects that visually mimic benign projects but contain hidden backdoors (using long whitespace and layered encodings/encryption). The malicious files retrieve next-stage payloads from domains such as dieserbenni.ru and 1312services.ru; the report provides extensive IOCs (domains, URLs, GitHub repos, and file hashes), analysis of the obfuscation/crypto used, and notes that GitHub removed the identified repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.