logo

Cyber Criminals Exploit GitHub and FileZilla to Deliver Malware Cocktail

ID: 79fbcc76-ce58-5c33-a578-f53c2de09af4

STIX ID: report--79fbcc76-ce58-5c33-a578-f53c2de09af4

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Recorded Future's Insikt Group warns of a multi-faceted malvertising and SEO-poisoning campaign dubbed 'GitCaught' that impersonates legitimate software via fake GitHub repositories and other cloud services to deliver a range of stealers and banking trojans (including RedLine, Vidar, Lumma, Raccoon, Atomic/AMOS, Octo, Rhadamanthys, DanaBot, and DarkComet) across Windows, macOS, and Android; actors also abuse FileZilla, Bitbucket, and Dropbox for delivery and management, and a macOS backdoor named 'Activator' is highlighted for disabling Gatekeeper, downloading staged Python payloads, and establishing persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.