logo

The Growing Abuse of GitHub and GitLab in Phishing Campaigns

ID: 76ad88c9-8938-50f7-aef1-62a2b31246ee

STIX ID: report--76ad88c9-8938-50f7-aef1-62a2b31246ee

Feed Name: Cofense Blog

Threat Score
72/100

Date Published: 2026-04-08

Date Updated: 2026-04-27

Author: Cofense

...
...

This Cofense Intelligence report analyzes the growing abuse of Git repository hosting (GitHub and GitLab) by threat actors to distribute malware (notably Remcos, DcRAT and other RATs/stealers) and host credential-phishing pages via GitHub/GitLab Pages and raw file downloads; it highlights trends (45% of observed campaigns in 2025), common TTPs (raw.githubusercontent downloads, github.io/gitlab.io pages, password-protected archives, user-agent detection and redirects), and the operational impact of trusted domains bypassing email/security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.