EXECUTIVE SUMMARY:
A campaign is targeting GitHub users by exploiting the platform’s "Issues" feature to distribute the Lumma Stealer malware. Threat actors open fake issues on popular open source repositories, falsely claiming that there is a security vulnerability. They lure users to visit a counterfeit domain, disguised as a legitimate security scanner, tricking them into downloading malicious software. GitHub’s email notifications amplify the threat, making it seem credible as the messages originate from official GitHub servers.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A campaign is targeting GitHub users by exploiting the platform’s "Issues" feature to distribute the Lumma Stealer malware. Threat actors open fake issues on popular open source repositories, falsely claiming that there is a security vulnerability. They lure users to visit a counterfeit domain, disguised as a legitimate security scanner, tricking them into downloading malicious software. GitHub’s email notifications amplify the threat, making it seem credible as the messages originate from official GitHub servers.[emaillocker id="1283"]
The scheme operates by leveraging GitHub's "Issues" feature, were attackers, posing as GitHub users, file issues on various repositories. These actions trigger automated email notifications from legitimate GitHub servers, prompting users to address the alleged security concern. The email contains a link to the counterfeit domain, where users are confronted with a false captcha designed to initiate the malware download. Once users interact with the captcha, JavaScript executes malicious code that copies instructions to the clipboard, instructing them to run a PowerShell script that downloads and executes a trojanized executable, 'l6E.exe.' This malware can steal sensitive information, including credentials, authentication cookies, and cryptocurrency wallets.
Users are strongly advised to remain vigilant and avoid clicking links or downloading attachments from unsolicited emails regarding security issues in repositories. These suspicious "issues" to GitHub is crucial for investigation and mitigation. This underscores the potential for popular platforms like GitHub to be misused for malicious purposes, emphasizing the importance of awareness among developers and users engaged in open-source projects.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1189 | Drive-by Compromise | |
| Execution | T1203 | Exploitation for Client Execution |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1003 | OS Credential Dumping |
| Collection | T1213 | Data from Information Repositories |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1565 | Data Manipulation |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/