Threat Actors Increasingly Abusing GitHub for Malicious Purposes
ID: e1b28b83-586a-56bb-b035-21ee13c43954
STIX ID: report--e1b28b83-586a-56bb-b035-21ee13c43954
Feed Name: The Hacker News
Threat Score
The report describes a growing trend where threat actors abuse GitHub and other legitimate cloud/code hosting services as "living-off-trusted-sites" (LOTS) to host payloads, act as dead-drop resolvers for C2, and sometimes for data exfiltration; it cites examples (rogue Python packages, Drokbk, ShellBox) and notes detection is difficult, recommending a mix of environment-specific detection strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
