logo

Fake Coding Challenges Steal Sensitive Data Via FogDoor.

ID: f5d711b7-0442-5581-8999-3394e7ab4da0

STIX ID: report--f5d711b7-0442-5581-8999-3394e7ab4da0

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-04-22

Date Updated: 2026-07-16

...
...

Cyble CRIL discovered a targeted campaign that lures Polish-speaking developers with a fake GitHub "FizzBuzz" recruitment challenge containing an ISO that executes a PowerShell script to install the "FogDoor" backdoor. FogDoor uses geofencing to target Polish victims, retrieves commands from a social media profile (Dead Drop Resolver), steals browser cookies, Wi‑Fi credentials, and user files, stages and uploads exfiltrated data to file-sharing services, notifies the attacker via temporary webhooks, and maintains persistence via a scheduled task; the report includes IOCs (file hashes, URLs), MITRE ATT&CK mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.