Hackers impersonate hundreds of brands on GitHub
Hackers impersonate hundreds of brands on GitHub to release malware, steal data into victim machines.
According to a report by the Help Net Security website, a research team from Arctic Wolf, a cybersecurity specialist company, has detected a campaign to spread malware of the type of theft of data from victims or Infostealer through the use of GitHub's Repo or Repositories by impersonating brands of a variety of famous tools - security tools, Crypto Wallets, financial applications, and up to 292 other types of software. The malware is capable of stealing a variety of data, whether it is
Data of malware-addicted systems
Cookies files and passwords are saved on various web browsers such as Chrome, Edge, Brave, Yandex, Vivaldi, Chromium, Tor, Epic, Opera, Opera GX, and Firefox.
Local Storage and Configuration data contained within the Web Browser Extension, especially the various Crypto Wallet add-ons.
Session Token In the Steam, Discord platform implementation, Password uses the Meta Max messaging application, and data contained within the Telegram application.
A file inside the Desktop and Documents folder containing the words "password," "passwords," "seeds," "keys," "wallet," "backup," and "recovery."
The password is saved within Windows Credential Manager.
These data are sent to a C2 or Command and Control server located on the IP Address number 193.143.1 [.] 131, which is hosted within Russia. All stolen files are created logs under the name browser _ decryption.log, and messages.log. If the file is found on the machine, it is malware infected.
In terms of software detection, the research team detected a fake software using its own company name, Arctic Wolf. When it went deeper, it was discovered that hackers had published a Repo impersonation page by pushing a search sequence to a page on the search engine, also known as the SEO (Search Engine Optimization) method. Each Repo page contained a manual document, or README. Inside it, there was a link that took the victim to a page supported by the hacker. The domain was * .github [.] io. Each page lured the download of a compressed file. A large Zip. The system on the page changes the name of the file and the malware file (Payload) every 60 seconds. The file set contains the real software, the WinGUP Updater update tool, and the libcurl.dll malware file. When the victim runs the software file, the Updater runs the malware DLL file, ultimately leading to the malware embedding.
The research team has not detected that the malware has modified the Run Key (Run Key), Task Scheduling, Add an Exclusion List in Microsoft Defender, or any other gambit to create Persistence on the system. However, it can only be seen as Smash and Grab malware or attached to speed up data theft before it is deleted.
# Trending # Lemon 8 Howtoo # lemon 8 diary # github # freedomhack
จากประสบการณ์ส่วนตัวในการใช้ GitHub และโปรแกรมโอเพนซอร์สต่าง ๆ ฉันเคยเจอเหตุการณ์ที่น่าสงสัยเกี่ยวกับ repo ที่ดูเหมือนจะเป็นของเครื่องมือที่รู้จัก แต่จริง ๆ แล้วเป็นของแฮกเกอร์ที่แอบอ้างแบรนด์ดังต่าง ๆ เพื่อหลอกให้ดาวน์โหลดมัลแวร์ จริง ๆ แล้วแฮกเกอร์พยายามใช้เทคนิค SEO ทำให้ repo เหล่านี้ติดอันดับสูง ๆ บนการค้นหา เพื่อให้ผู้ใช้ทั่วไปเกิดความเชื่อถือและดาวน์โหลดไฟล์ zip ที่ซ่อนมัลแวร์ไว้ เมื่อเปิดใช้งาน ไฟล์ DLL ของมัลแวร์ก็ถูกเปิดทำงาน ทำให้ข้อมูลสำคัญในเครื่อง เช่น รหัสผ่านที่บันทึกในเบราว์เซอร์ หรือ session token ของแอปพลิเคชันต่าง ๆ ถูกขโมยไปได้อย่างง่ายดาย ฉันแนะนำให้ผู้ใช้งาน GitHub ระมัดระวังการดาวน์โหลดซอฟต์แวร์จากแหล่งที่ไม่น่าเชื่อถือ และควรเปิดการใช้งานสองชั้น (Two-Factor Authentication) ในบริการออนไลน์ที่ใช้อยู่เสมอ นอกจากนี้ การตรวจสอบไฟล์ชื่อ browser_decryption.log หรือ sends.log บนเครื่องก็เป็นอีกหนึ่งวิธีช่วยตรวจจับเบื้องต้นว่าเครื่องอาจติดมัลแวร์ประเภทนี้ อีกสิ่งที่ควรระวังคือ แฮกเกอร์ไม่ได้ใช้วิธีการฝังมัลแวร์ถาวรบนระบบ จึงเป็นลักษณะมัลแวร์ที่เน้นขโมยข้อมูลรวดเร็วแล้วลบทิ้ง การอัปเดตซอฟต์แวร์ป้องกันไวรัสและใช้โปรแกรมรักษาความปลอดภัยที่เชื่อถือได้จึงมีความสำคัญอย่างยิ่ง เพื่อป้องกันการโจมตีและลดโอกาสติดมัลแวร์ชนิดนี้ได้อย่างมีประสิทธิภาพ โดยรวมแล้วกรณีนี้สอนให้รู้ว่าการแอบอ้างแบรนด์บนแพลตฟอร์มสาธารณะอย่าง GitHub สามารถเป็นช่องโหว่สำคัญที่แฮกเกอร์ใช้ในการโจมตี ฉะนั้นผู้ใช้งานควรรู้จักวิธีสังเกตและเลือกดาวน์โหลดเฉพาะจากแหล่งที่น่าเชื่อถือเท่านั้น
