Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters
As part of a campaign seen in April 2025, threat actors are using public GitHub repositories to host malicious payloads and disseminate them via Amadey.
In a report released today, Cisco Talos researchers Chris Neal and Craig Jackson claimed that the MaaS [malware-as-a-service] operators hosted payloads, tools, and Amadey plug-ins using fictitious GitHub accounts, perhaps in an effort to get around web filtering and for convenience.
According to the cybersecurity firm, the attack chains use a malware loader named Emmenhtal (also known as PEAKLIGHT) to distribute Amadey, which downloads several custom payloads from open GitHub repositories run by the threat actors.
The action is tactically similar to an email phishing operation that distributed SmokeLoader via Emmenhtal in Februar...

