Hackers Using Cracked Software on GitHub to Spread RisePro Info Stealer
ID: 9ef8b19a-f902-512e-9505-26cfdabe7d79
STIX ID: report--9ef8b19a-f902-512e-9505-26cfdabe7d79
Feed Name: The Hacker News
Threat Score
Researchers discovered 17 GitHub repositories (11 accounts) offering cracked software that link to password-protected RAR archives on digitalxnetwork.com which install a loader that injects the RisePro (v1.6) information stealer into legitimate binaries (AppLaunch.exe or RegAsm.exe); the campaign uses evasion techniques (inflated executables to disrupt analysis) and exfiltrates stolen data to Telegram channels, and Microsoft/G DATA have taken the repositories down.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
