Security News > 2023 > June > Fake zero-day PoC exploits on GitHub push Windows, Linux malware

Fake zero-day PoC exploits on GitHub push Windows, Linux malware
2023-06-14 10:00

Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Windows and Linux with malware.

These malicious exploits are promoted by alleged researchers at a fake cybersecurity company named 'High Sierra Cyber Security,' who promote the GitHub repositories on Twitter, likely to target cybersecurity researchers and firms involved in vulnerability research.

In all cases, the malicious repositories host a Python script that acts as a malware downloader for Linux and Windows systems.

The malware is saved to the Windows %Temp% or the Linux /home//.

North Korean Lazarus state-sponsored hacking group conducted a similar campaign in January 2021, when they created fake vulnerability researcher personas on social media to target researchers with malware and zero-days.

More recently, academics found thousands of repositories on GitHub offering fake proof-of-concept exploits for various vulnerabilities, some of them infecting users with malware, malicious PowerShell, obfuscated info-stealer downloaders, Cobalt Strike droppers, and more.


News URL

https://www.bleepingcomputer.com/news/security/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 17 377 2459 1528 666 5030
Github 12 3 42 30 15 90