Kaspersky Says Hackers Are Creating Fake GitHub Projects to Steal Crypto

robot
Abstract generation in progress

Cybersecurity company Kaspersky claims hackers are creating hundreds of fake GitHub projects meant to fool users into downloading crypto and credential-stealing malware.According to Kaspersky analyst Georgy Kucherin in a report released on February 24, the malware campaign that the company labelled “GitVenom” has seen hackers creating hundreds of repositories on GitHub hosting remote access trojans (RATs), info-stealers, and clipboard hijackers.

Hackers Give Fake Bitcoin Wallets To Victims

A Telegram bot manages Bitcoin wallets, and a tool automates Instagram account interactions, both of which are fake.It included “well-designed” information and instruction files “probably generated by using AI tools.” Kucherin also said the malware makers “went to great lengths” to make the projects look real.Along with adding multiple references to particular changes to give the impression that the project was actively improving, those behind the malevolent projects also lied about the number of “commits,” or changes to the project.To do that, they put a timestamp file in these repositories and make changes to it every few minutes.

Kaspersky finds that these projects generally “performed meaningless actions,” as they did not apply the features discussed in the instruction and explainer files.

Kaspersky found several fake projects from at least two years ago and has used the same “infection vector” for a long time since the hackers have been attracting victims for a while.According to Kucherin, all the fake projects have “malicious payloads” that download parts like an info stealer that sends saved credentials, bitcoin wallet data, and browsing history and uploads it to the hackers via Telegram.Another bad part is using a clipboard and replacing crypto wallet addresses and replacing them with ones controlled by the attacker.

Hackers Use Fake Telegram Bots To Trick People

According to Kucherin, one user was caught by these malicious apps last year in November when a wallet controlled by hackers got 5 Bitcoins, which are worth about $442,000 today.Kaspersky reports that this GitVenom campaign targets users in Russia, Brazil, and Turkey, but it has now spread worldwide.Kucherin says that since millions of developers all around use code-sharing sites like GitHub, that’s why these threat actors will keep using fake software to spread malware.Kucherin suggests that you see the actions of third-party code before downloading anything. He added the company anticipated attackers to present “possibly with small changes” to methods, techniques, and procedures.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)