Fraud & Identity Theft

Threat Actors Abuse GitHub to Distribute Multiple Information Stealers

Russian-speaking threat actors are caught abusing a GitHub profile to distribute information stealers posing as legitimate software.

Russian-speaking threat actors are caught abusing a GitHub profile to distribute information stealers posing as legitimate software.

Threat intelligence firm Recorded Future on Tuesday raised an alarm for a malicious campaign abusing a legitimate GitHub profile to distribute information stealing malware.

As part of the campaign, Russian-speaking threat actors operating out of the Commonwealth of Independent States (CIS) have been distributing Atomic macOS Stealer (AMOS), Vidar, Lumma, and Octo malware by impersonating legitimate applications such as 1Password, Bartender 5, and Pixelmator Pro.

The malware operations shared the same command-and-control (C&C) infrastructure, suggesting that a centralized setup was used in cross-platform attacks, likely to increase efficiency, Recorded Future notes in a new report (PDF).

Early 2024 industry reporting showed that AMOS was being distributed through deceptive websites, impersonating legitimate macOS applications, including an installation file for Slack, and via fraudulent Web3 gaming projects.

Using these reports as a starting point, Recorded Future identified 12 websites advertising legitimate macOS software but redirecting victims to a GitHub profile distributing AMOS instead. The profile was also seen distributing the Octo Android banking trojan and various Windows infostealers.

The GitHub profile, belonging to a user named ‘papinyurii33’, was created on January 16, 2024 and contained only two repositories. Recorded Future said its researchers observed multiple changes made to the files in these repositories in February and early March, but no new activity since March 7.

Advertisement. Scroll to continue reading.

The investigation also revealed the use of a FileZilla file transfer protocol FTP server for malware management and for distributing the Lumma and Vidar information stealers.

In addition, Recorded Future said it discovered several IP addresses associated with the campaign, including four IPs associated with the C&C infrastructure for the DarkComet RAT and a FileZilla FTP server used for distributing it. Between August 2023 and February 2024, Raccoon Stealer was also distributed using these FTP servers.

Corroborating the findings with reports from Cyfirma, CERT-UA, Cyble, and Malwarebytes, Recorded Future concluded that they refer to attacks orchestrated by the same threat actor as part of a large-scale campaign.

The cybersecurity firm advises organizations to use automated code scanning tools to perform code assessments for all code obtained from external repositories and to identify potential malware or suspicious patterns.

Related: 21 New Mac Malware Families Emerged in 2023

Related: Threat Actors Manipulate GitHub Search to Deliver Malware

Related: Ransomware Declines as InfoStealers and AI Threats Gain Ground

Related Content

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Cyberwarfare

The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage...

Vulnerabilities

The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.

Government

UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.

Malware & Threats

Turla has been using the backdoor against government and military organizations in Ukraine for espionage.

Endpoint Security

A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version