Security News > 2023 > June > Fake zero-day PoC exploits on GitHub push Windows, Linux malware
Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Windows and Linux with malware.
These malicious exploits are promoted by alleged researchers at a fake cybersecurity company named 'High Sierra Cyber Security,' who promote the GitHub repositories on Twitter, likely to target cybersecurity researchers and firms involved in vulnerability research.
In all cases, the malicious repositories host a Python script that acts as a malware downloader for Linux and Windows systems.
The malware is saved to the Windows %Temp% or the Linux /home//.
North Korean Lazarus state-sponsored hacking group conducted a similar campaign in January 2021, when they created fake vulnerability researcher personas on social media to target researchers with malware and zero-days.
More recently, academics found thousands of repositories on GitHub offering fake proof-of-concept exploits for various vulnerabilities, some of them infecting users with malware, malicious PowerShell, obfuscated info-stealer downloaders, Cobalt Strike droppers, and more.
News URL
Related news
- New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus (source)
- Botnet exploits GeoVision zero-day to install Mirai malware (source)
- RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks (source)
- BootKitty UEFI malware exploits LogoFAIL to infect Linux systems (source)
- Mitel MiCollab zero-day and PoC exploit unveiled (source)
- New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools (source)
- 390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits (source)
- Russia targets Ukrainian conscripts with Windows, Android malware (source)
- New Windows Themes zero-day gets free, unofficial patches (source)
- Windows Themes zero-day bug exposes users to NTLM credential theft (source)