Malware-as-a-service caught using GitHub to distribute its payloads

Malware-as-a-service caught using GitHub to distribute its payloads

A recent investigation by Cisco’s Talos security team has revealed a malware-as-a-service (MaaS) operator leveraging public GitHub accounts to disseminate various forms of harmful software. This tactic utilized GitHub’s reputation as a trusted platform, often allowed within enterprise networks that depend on the code repository for software development. Following the alert from Talos, GitHub promptly removed the three accounts associated with the malicious payloads. According to researchers Chris Neal and Craig Jackson, the straightforward file hosting capabilities of GitHub can enable malware distribution while potentially evading web filtering systems that fail to block the GitHub domain. They noted, "While some organizations can restrict GitHub access to mitigate the risks of open-source offensive tools and malware, many development teams require GitHub access, making it challenging to distinguish between legitimate traffic and malicious downloads." The ongoing campaign, identified by Talos since February, has been utilizing a previously recognized malware loader known as Emmenhtal, also referred to as PeakLight. This loader had also been documented by Palo Alto Networks and Ukraine’s major state cyber agency, SSSCIP, which highlighted its use in campaigns that targeted Ukrainian entities via malicious emails. In this recent MaaS operation, Talos discovered the same variant of Emmenhtal, but the method of distribution through GitHub marked a significant shift. Whereas the earlier Ukrainian-focused operation deployed a malicious backdoor called SmokeLoader, the GitHub distribution directed users to install Amadey, another known malware platform. Amadey, which first emerged in 2018 for botnet assembly, primarily serves to gather system information from compromised devices and download tailored secondary payloads designed for specific campaign objectives.

Sources : Ars Technica

Published On : Jul 17, 2025, 22:20

Cybersecurity
Sam Bankman-Fried's Political Pivot Fails to Impress Trump’s Justice Department

Since Donald Trump’s presidency began, the founder of FTX, Sam Bankman-Fried, has been on a mission to rebrand himself a...

Ars Technica | Mar 12, 2026, 19:00
Sam Bankman-Fried's Political Pivot Fails to Impress Trump’s Justice Department
AI
Perplexity Launches Innovative AI Tool for Desktop Users

In an exciting development for AI enthusiasts, Perplexity has introduced its latest innovation: the 'Personal Computer.'...

Ars Technica | Mar 12, 2026, 17:45
Perplexity Launches Innovative AI Tool for Desktop Users
Startups
Adobe's Leadership Shake-Up: CEO Shantanu Narayen to Step Down Amid Transition

In a significant corporate shift, Adobe has announced that its CEO, Shantanu Narayen, will be stepping down once a succe...

CNBC | Mar 12, 2026, 20:25
Adobe's Leadership Shake-Up: CEO Shantanu Narayen to Step Down Amid Transition
AI
Atlassian Embraces AI Revolution with Significant Workforce Reductions

In a bold move reflecting the growing influence of artificial intelligence, Atlassian, the Australian productivity softw...

TechCrunch | Mar 12, 2026, 17:45
Atlassian Embraces AI Revolution with Significant Workforce Reductions
Automotive
Tesla Enters UK Energy Market, Challenging Established Utilities

Tesla has officially secured a license to operate as a utility in the United Kingdom, marking a significant expansion in...

TechCrunch | Mar 12, 2026, 17:01
Tesla Enters UK Energy Market, Challenging Established Utilities
View All News