Researchers Uncover Ring of GitHub Accounts Promoting 300+ Backdoored Apps

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12J7OJO8ybeOH33qpHb8sH6YHe=a3Gpez0aVSvo1i-y0Yg@mail.gmail.com>
'A security researcher has uncovered a ring of malicious GitHub
accounts promoting over 300 backdoored Windows, Mac, and Linux
applications and software libraries. The malicious apps contained code
to gain boot persistence on infected systems and later download other
malicious code -- which appeared to be a "sneaker bot," a piece of
malware that would add infected systems to a botnet that would later
participate in online auctions for limited edition sneakers.

All the GitHub accounts that were hosting these files -- backdoored
versions of legitimate apps -- have now been taken down. One account,
in particular, registered in the name of Andrew Dunkins, hosted 305
backdoored ELF binaries. Another 73 apps were hosted across 88 other
accounts. '

-- source: https://developers.slashdot.org/story/19/03/05/1351217

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.