Stargazer Goblin, a threat actor, has established a network of phony GitHub accounts to power a Distribution-as-a-Service (DaaS) that disseminates several malwares that steal information, generating $100,000 in illegal revenue for them in the last year.
Check Point has named the network the “Stargazers Ghost Network,” claiming that it consists of over 3,000 accounts on the cloud-based code hosting platform and thousands of repositories that are used to spread malware or harmful links.
This technique has been used to spread malware families such as Atlantida Stealer, Rhadamanthys, RisePro, Lumma Stealer, and RedLine. To give the false accounts the appearance of authenticity, they have also been starring, forking, watching, and subscribing to harmful repositories read more about Stargazer Goblin Creates 3000 Fake GitHub Accounts for Malware Spread.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
