Threat Advisory

GitHub Scanner Campaign Distributes Lumma Stealer via Fake Vulnerabilities

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A campaign is targeting GitHub users by exploiting the platform’s "Issues" feature to distribute the Lumma Stealer malware. Threat actors open fake issues on popular open source repositories, falsely claiming that there is a security vulnerability. They lure users to visit a counterfeit domain, disguised as a legitimate security scanner, tricking them into downloading malicious software. GitHub’s email notifications amplify the threat, making it seem credible as the messages originate from official GitHub servers.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A campaign is targeting GitHub users by exploiting the platform’s "Issues" feature to distribute the Lumma Stealer malware. Threat actors open fake issues on popular open source repositories, falsely claiming that there is a security vulnerability. They lure users to visit a counterfeit domain, disguised as a legitimate security scanner, tricking them into downloading malicious software. GitHub’s email notifications amplify the threat, making it seem credible as the messages originate from official GitHub servers.[emaillocker id="1283"]

The scheme operates by leveraging GitHub's "Issues" feature, were attackers, posing as GitHub users, file issues on various repositories. These actions trigger automated email notifications from legitimate GitHub servers, prompting users to address the alleged security concern. The email contains a link to the counterfeit domain, where users are confronted with a false captcha designed to initiate the malware download. Once users interact with the captcha, JavaScript executes malicious code that copies instructions to the clipboard, instructing them to run a PowerShell script that downloads and executes a trojanized executable, 'l6E.exe.' This malware can steal sensitive information, including credentials, authentication cookies, and cryptocurrency wallets.

Users are strongly advised to remain vigilant and avoid clicking links or downloading attachments from unsolicited emails regarding security issues in repositories. These suspicious "issues" to GitHub is crucial for investigation and mitigation. This underscores the potential for popular platforms like GitHub to be misused for malicious purposes, emphasizing the importance of awareness among developers and users engaged in open-source projects.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1566 Phishing
T1189 Drive-by Compromise
Execution T1203 Exploitation for Client Execution
Persistence T1547 Boot or Logon Autostart Execution
 Defense Evasion  T1027 Obfuscated Files or Information
Credential Access T1003 OS Credential Dumping
Collection T1213 Data from Information Repositories
 Command and Control T1071 Application Layer Protocol
Exfiltration  T1041 Exfiltration Over C2 Channel
 Impact T1565 Data Manipulation

 

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/

[/emaillocker]
crossmenu