Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters

As part of a campaign seen in April 2025, threat actors are using public GitHub repositories to host malicious payloads and disseminate them via Amadey.

In a report released today, Cisco Talos researchers Chris Neal and Craig Jackson claimed that the MaaS [malware-as-a-service] operators hosted payloads, tools, and Amadey plug-ins using fictitious GitHub accounts, perhaps in an effort to get around web filtering and for convenience.

According to the cybersecurity firm, the attack chains use a malware loader named Emmenhtal (also known as PEAKLIGHT) to distribute Amadey, which downloads several custom payloads from open GitHub repositories run by the threat actors.

The action is tactically similar to an email phishing operation that distributed SmokeLoader via Emmenhtal in February 2025 in assaults against Ukrainian organizations using lures connected to billing and invoice payment.

Although Amadey has also been known to distribute ransomware such as LockBit 3.0 in the past read more about Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers Bypassing Filters

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *