Stargazer Goblin created a network of fake GitHub accounts to distribute malware

30 July 2024 1 minute Author: Newsman

Stargazer Goblin has created a network of over 3,000 fake GitHub accounts to distribute malware**. This network is known as the Stargazers Ghost Network and is used to distribute various malware, including Atlantida Stealer, Rhadamanthys, RisePro, Lumma Stealer and RedLine. Over the past year, it has brought criminals about $100,000 in illegal profits. Fake accounts engage in star status, forking, tracking, and subscribing to malicious repositories to give them the appearance of legitimacy.

**The network has been active since August 2022, although the DaaS ad didn’t appear until July 2023**. Attackers operate a network of “ghost” accounts that distribute malware via malicious links in repositories and encrypted archives as releases. Using multiple account categories helps make the infrastructure more resilient to GitHub’s attempts to remove malicious content.

This sophisticated malware distribution operation demonstrates how attackers use legitimate platforms for their purposes, remaining undetected and minimizing damage when removing malicious repositories.

Other related articles
Found an error?
If you find an error, take a screenshot and send it to the bot.