Cyber Criminals Exploit GitHub and FileZilla to Deliver Malware Cocktail
ID: 79fbcc76-ce58-5c33-a578-f53c2de09af4
STIX ID: report--79fbcc76-ce58-5c33-a578-f53c2de09af4
Feed Name: The Hacker News
Recorded Future's Insikt Group warns of a multi-faceted malvertising and SEO-poisoning campaign dubbed 'GitCaught' that impersonates legitimate software via fake GitHub repositories and other cloud services to deliver a range of stealers and banking trojans (including RedLine, Vidar, Lumma, Raccoon, Atomic/AMOS, Octo, Rhadamanthys, DanaBot, and DarkComet) across Windows, macOS, and Android; actors also abuse FileZilla, Bitbucket, and Dropbox for delivery and management, and a macOS backdoor named 'Activator' is highlighted for disabling Gatekeeper, downloading staged Python payloads, and establishing persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
