GitHub Service Abused by Attackers to Host Phishing Kits
#1
Quote:Malicious actors hosted phishing kits on the web-based GitHub code hosting platform by abusing the service's free repositories to deliver them to their targets via github.io domains.
 
This technique allows crooks to take advantage of the GitHub Pages service to bypass both whitelists and network defenses, just like the "use of large consumer cloud storage sites, social networking, and commerce services such as Dropbox, Google Drive, Paypal, Ebay, and Facebook" makes it possible to have their malicious activities blend in within legitimate web traffic.
 
The researchers state that GitHub took down all the accounts discovered to be involved in the malicious activity as of April 19, 2019, while also being "extremely responsive in addressing this abuse of their systems."
 
As discovered by Proofpoint's research team, multiple threat actors used github.io domains as part of various malicious campaigns including phishing attacks which directed victims to landing pages hosted on GitHub's service.

SOURCE: https://www.bleepingcomputer.com/news/se...hing-kits/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft promises faster Windows 11, f...
Windows 11 Update Br...harlan4096 — 12:07
ScreenToGif 2.43
ScreenToGif 2.43 ...harlan4096 — 07:37
Microsoft Edge 146.0.3856.72
Version 146.0.3856...harlan4096 — 07:35
Brave 1.88.134 (Chromium 146.0.7680.153)
Release v1.88.134 ...harlan4096 — 07:34
Vivaldi 7.9 Build 3970.41
Vivaldi 7.9 Build ...harlan4096 — 07:33

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (43)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>