Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Meta Earth Network 2.0: Pioneering Web3 Innovation with Rewards and Global Events

The more sustainability and transparency you get, the better your decisions will be

Successful In-house SOC 6 steps up to 24 hours a day, 365 days a year

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Troilerization Github repository found in a campaign targeting 67 gamers and developers
Identity

Troilerization Github repository found in a campaign targeting 67 gamers and developers

userBy userJune 20, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Trojanized Github

Cybersecurity researchers have published more than 67 Github repositories that threat actors claim to provide Python-based hacking tools, but have discovered a new campaign that instead offers Trojanized Payloads.

The activity, called Banana Squad by ReversingLabs, was downloaded more than 75,000 times in 2023 and is rated as a continuation of the Rogue Python campaign targeting Python Package Index (PYPI) repository with fake packages with information-type capabilities on Windows systems.

The findings were built on a previous report from SANS’s Internet Storm Center in November 2024, and detailed the “Steam-Account-Checker” tool hosted on Github.[.]ru “).

Further analysis of repositories and attacker-controlled infrastructure has discovered 67 Trojanized Github repositories impersonating benign repositories of the same name.

Cybersecurity

There is evidence to suggest that users searching for software such as account cleaning tools, Discord account cleaners, Fortnite external cheats, Tiktok username checkers, and game cheats such as PayPal Bulk account checkers are the targets of the campaign. All identified repositories were subsequently deleted by GitHub.

“Backdoors and troilerization code in public source code repositories like GitHub are becoming more common and representing the growth of software supply chain attack vectors.”

“For developers who rely on these open source platforms, it’s essential to always reaffirm that the repository they use contains what they really expect.”

Github as a malware distribution service

Development is increasingly occurring as Github is becoming the focus of several campaigns as a malware delivery vector. Earlier this week, Trend Micro said it had discovered 76 malicious Github repositories run by threat actors called Water Curses to provide multi-stage malware.

These payloads are designed to suck up your credentials, browser data, and session tokens, providing threat actors with permanent remote access to compromised systems.

Next, we use a criminal service known as the Stargazers Ghost Network to check for Point Point light on another campaign targeting Minecraft users with Java-based malware. The Stargazers Ghost Network refers to a collection of GitHub accounts that propagate malware or malicious links through a phishing repository.

“The network consists of multiple accounts that distribute malicious links and malware and perform other actions that perform other actions, such as starring, forking, or registering with malicious repositories.

Cybersecurity companies also rated that such “github ‘ghost” accounts are merely part of the epic photo, while other “ghost” accounts operate on different platforms as an integral part of the larger distribution universe as a service.

Several aspects of the Stargazers Ghost Network were published by CheckMarx in April 2024, calling a pattern of threat actors that uses fake stars to push out frequent updates to artificially inflate the popularity of the repository, and confirm that it is rising above GitHub search results.

These repositories are cleverly disguised as legitimate projects related to tools such as popular games, cheats, cryptocurrency price trackers, and crash betting games, such as multiplier prediction.

These campaigns also weave in another attack wave targeting novice cybercriminals, aiming to be easily available malware and attack tools on Github with a backdoid repository, infecting information stolen items.

In one example highlighted by Sophos this month, the troilized Sakura Rat repository was found to incorporate malicious code that compromised people who used information stolen items and other remote access trojans (RATs) to compile malware on their systems.

The identified repository acts as a conduit for visual studio pre-build events, Python scripts, screensaver files, and four types of backdoors embedded in JavaScript, stealing data, communicating via telegram, fetching more payloads, including Ashnararat, Remkosrat and Ranmasteel.

Cybersecurity

Overall, the cybersecurity company said it had detected over 133 backloo repositories as part of its campaign, with 111 detecting Builidd backdoors and others hosting Python, Screensaver and JavaScript backdoors.

Sophos also noted that these activities are linked to Distribution as a Service (DAAS) operations that have been operating since August 2022, and using thousands of Github accounts to distribute malware embedded in Trojanized repositories, with a focus on game cheats, exploitations and attack tools.

The exact distribution method used in the campaign is unknown, but threat actors are also thought to rely on Discord servers and YouTube channels to spread links to Trojanized repositories.

“It remains unclear whether this campaign directly links to whether some or all of the previous campaigns have been reported, but the approach appears to be popular and effective and is likely to continue in some way,” Sophos said. “In the future, the focus may change and threat actors may target other groups other than unfamiliar cybercriminals and gamers who use cheats.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFounder of Robin Hood, who could revolutionize energy if he succeeds
Next Article Sustainable 6G network in urban areas
user
  • Website

Related Posts

Successful In-house SOC 6 steps up to 24 hours a day, 365 days a year

June 20, 2025

A massive 7.3 TBPS DDOS attack targets hosting providers and delivers 37.4 TB in 45 seconds

June 20, 2025

New Android Malware Surges Hit Your Device Through Overlay, Virtualization Scams, NFC Theft

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Meta Earth Network 2.0: Pioneering Web3 Innovation with Rewards and Global Events

The more sustainability and transparency you get, the better your decisions will be

Successful In-house SOC 6 steps up to 24 hours a day, 365 days a year

A massive 7.3 TBPS DDOS attack targets hosting providers and delivers 37.4 TB in 45 seconds

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meta Earth Network 2.0: Pioneering Web3 Innovation with Rewards and Global Events

Top 10 Startups and High-Tech Funding News – June 19, 2025

Sifflet raises $18 million to power AI using reliable data as a demand for observability

Is WhatsApp becoming a weapon of war?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.