HomeSecurityFake zero-day PoC exploits on GitHub spread Windows and Linux malware

Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept (PoC) exploits for zero-day vulnerabilities that infect Windows and Linux systems with malware.

Fake zero-day PoC exploits on GitHub spread Windows and Linux malware
Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

These malicious exploits are being promoted by alleged researchers from a fake cybersecurity company called “High Sierra Cyber ​​Security,” who are promoting GitHub repositories on Twitter, likely targeting cybersecurity researchers and companies involved in vulnerability research.

The repositories appear legitimate, and the users who maintain them impersonate real security researchers from Rapid7 and other security companies, even using their headshots.

Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

The same personalities maintain Twitter accounts to help lend legitimacy to their research, code repositories like GitHub, and draw victims from the social networking platform.

This campaign was discovered by VulnCheck, which reports that it has been ongoing since at least May 2023, promoting alleged exploits for zero-day flaws in popular software such as Chrome, Discord, Signal, WhatsApp, and Microsoft Exchange.

Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

In all cases, the malicious repositories host a Python script ('poc.py') that acts as a malware downloader for Linux and Windows systems.

The script downloads a ZIP file from an external URL to the victim's computer depending on their operating system, with Linux users downloading 'cveslinux.zip' and Windows users receiving 'cveswindows.zip.'

The malware is stored in the Windows %Temp% or Linux /home//.local/share folders, extracted, and executed.

 PoC GitHub

VulnCheck reports that the Windows binary contained in the ZIP ('cves_windows.exe') is flagged by over 60% of AV engines on VirusTotal. The Linux binary ('cves_linux') is much more stealthy, being caught by only three scanners.

It's unclear what kind of malware is being installed, but both executables install a TOR client, and the Windows version has some detections as a password-stealing Trojan.

While the success of this campaign is unclear, VulnCheck notes that threat actors appear persistent - creating new accounts and repositories when existing ones are reported and removed.

Currently, these seven GitHub repositories, available at the time of writing, should be avoided:

  1. github.com/AKuzmanHSCS/Microsoft-Exchange-RCE
  2. github.com/MHadzicHSCS/Chrome-0-day
  3. github.com/GSandersonHSCS/discord-0-day-fix
  4. github.com/BAdithyaHSCS/Exchange-0-Day
  5. github.com/RShahHSCS/Discord-0-Day-Exploit
  6. github.com/DLandonHSCS/Discord-RCE
  7. github.com/SsankkarHSCS/Chromium-0-Day

Furthermore, these Twitter accounts belong to impersonators and you should not trust them.

  • twitter.com/AKuzmanHSCS
  • twitter.com/DLandonHSCS
  • twitter.com/GSandersonHSCS
  • twitter.com/MHadzicHSCS
Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Security researchers and cybersecurity enthusiasts should be cautious when downloading scripts from unknown repositories, as impersonation is always a possibility.

The North Korean state-backed hacking group Lazarus conducted a similar campaign in January 2021, creating fake vulnerability researcher personas on social media to target researchers with malware and zero-days.

Later that year, they targeted researchers with trojanized versions of the reverse-engineered IDA Pro software to install remote access trojans.

More recently, academics have found thousands of repositories on GitHub offering fake proof-of-concept (PoC) exploits for various vulnerabilities, some of which infect users with malware, malicious PowerShell, obfuscated info-stealer downloaders, Cobalt Strike droppers, and more.

By targeting the vulnerability research and cybersecurity communities, threat actors can gain access to vulnerability research that can be used in their own attacks.

Even worse, in many cases, malware can provide initial access to a cybersecurity company's network, leading to further data theft and extortion attempts.

As cybersecurity companies tend to hold sensitive customer information, such as vulnerability assessments, remote access credentials, and even undisclosed zero-day vulnerabilities, this kind of access can be very valuable to threat actors.

Therefore, when downloading code from GitHub, it is imperative to check all code for malicious behavior. In this case, downloading and executing malware is clearly visible in PoCs, but this may not be true in all cases where threat actors may be hiding their malicious code.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS