Kaspersky Says Hackers Are Creating Fake GitHub Projects to Steal Crypto

TodayqNews

Cybersecurity company Kaspersky claims hackers are creating hundreds of fake GitHub projects meant to fool users into downloading crypto and credential-stealing malware.According to Kaspersky analyst Georgy Kucherin in a report released on February 24, the malware campaign that the company labelled “GitVenom” has seen hackers creating hundreds of repositories on GitHub hosting remote access trojans (RATs), info-stealers, and clipboard hijackers.

Hackers Give Fake Bitcoin Wallets To Victims

A Telegram bot manages Bitcoin wallets, and a tool automates Instagram account interactions, both of which are fake.It included “well-designed” information and instruction files “probably generated by using AI tools.” Kucherin also said the malware makers “went to great lengths” to make the projects look real.Along with adding multiple references to particular changes to give the impression that the project was actively improving, those behind the malevolent projects also lied about the number of “commits,” or changes to the project.To do that, they put a timestamp file in these repositories and make changes to it every few minutes.

Kaspersky finds that these projects generally “performed meaningless actions,” as they did not apply the features discussed in the instruction and explainer files.

Kaspersky found several fake projects from at least two years ago and has used the same “infection vector” for a long time since the hackers have been attracting victims for a while.According to Kucherin, all the fake projects have “malicious payloads” that download parts like an info stealer that sends saved credentials, bitcoin wallet data, and browsing history and uploads it to the hackers via Telegram.Another bad part is using a clipboard and replacing crypto wallet addresses and replacing them with ones controlled by the attacker.

Hackers Use Fake Telegram Bots To Trick People

According to Kucherin, one user was caught by these malicious apps last year in November when a wallet controlled by hackers got 5 Bitcoins, which are worth about $442,000 today.Kaspersky reports that this GitVenom campaign targets users in Russia, Brazil, and Turkey, but it has now spread worldwide.Kucherin says that since millions of developers all around use code-sharing sites like GitHub, that’s why these threat actors will keep using fake software to spread malware.Kucherin suggests that you see the actions of third-party code before downloading anything. He added the company anticipated attackers to present “possibly with small changes” to methods, techniques, and procedures.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)