Tuesday, April 23, 2024

Hackers Abuse GitHub Service to Host Variety of Phishing Kits to Steal Login Credentials

Hackers abuse popular code repositories service such as GitHub to host a variety of phishing domains to make their targets to believe it is through github.io domains.

By using well-known services like Dropbox, Google Drive, Paypal, eBay, and Facebook, attackers able to bypass whitelists and network defenses.

Proofpoint identified a range of malicious activities that target users from various organizations. Here is the Example of a phishing kit hosted on GitHub service that lures the login credentials of a retail bank.

GitHub service

Threat actors use github.io based landing pages to make the victims believe it is from the trusted source and to bypass traditional security solutions. The Phishing page uses the stolen brand logo and the graphics.

“In most cases of GitHub abuse described here, threat actors establish a canonical code repository site within the github.io canonical domain that resembles the brand they are abusing”, reads Proofpoint blog post.

app-l0gin- [.] github [.] io

Source code analysis reveals that the HTML script is slightly obfuscated and the lured credentials are sent to another compromised server that owned by attackers. Attackers use public GitHub landing page with PHP script loaded from remote servers.

GitHub service

Some threat actors use github.io domain only as a traffic redirector, “we were able to observe when actors made changes to their hosted web pages and most kits are not written from scratch and are instead simply modified by different actors.”

Proofpoint reported the abuse to GitHub and all the phishing accounts has been taken down by GitHub.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gentoo Linux GitHub Account Hacked, Attackers Modified Repositories

Hacker disclosed GitHub secret key hunter – TruffleHog

GitHub Announces Unlimited Private Repositories For Free Plan

Website

Latest articles

Malicious PyPI Package Attacking Discord Users To Steal Credentials

Hackers often target PyPI packages to exploit vulnerabilities and inject malicious code into widely...

Beware Of Weaponized Zip Files That Deliver WINELOADER Malware

APT29, a Russian threat group, targeted German political parties with a new backdoor called...

Citrix UberAgent Flaw Let Attackers Elevate Privileges

A significant vulnerability has been identified in Citrix's monitoring tool, uberAgent.If exploited, this flaw...

Hackers Group Claims To Have Broke Into IDF & Stolen Documents

Anonymous claims a successful cyberattack against the Israeli Defence Force (IDF), gaining access to...

VMware ESXi Shell Service Exploit on Hacking Forums: Patch Now

A new exploit targeting VMware ESXi Shell Service has been discovered and is circulating...

Windows MagicDot Path Flaw Lets Attackers Gain Rootkit-Like Abilities

A new vulnerability has been unearthed, allowing attackers to gain rootkit-like abilities on Windows...

Alert! Zero-day Exploit For WhatsApp Advertised On Hacker Forums

A zero-day exploit targeting the popular messaging app WhatsApp has been advertised on underground...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

WAAP/WAF ROI Analysis

Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles