HomeSecurityPhishing tool "GoIssue" targets GitHub users

“GoIssue” phishing tool targets GitHub users

Researchers discovered the GoIssue, which targets GitHub and is distributed on forums related to cybercrime.

GitHub GoIssue

This tool facilitates mass credential theft and emailing to users by extracting email addresses from public profiles. GoIssue is being offered to potential hackers for $700 for a customized version or $3,000 for full access to the source code. It combines mass mailing with advanced data collection capabilities, ensuring the anonymity of the operator through proxy networks.

Read also: Vulnerability in GitHub Enterprise allows Authentication Bypass

Developers are now a high-profile target for threat actors, as they can provide access to valuable source code that facilitates supply chain attacks. GitHub, as a leading online repository, has already been targeted by malicious campaigns targeting its users. The emergence of GoIssue marks a new era of attacks, where hackers are exploiting trusted developer environments to execute mass and customized phishing campaigns.

Through these campaigns, hackers can steal credentials and distribute malicious payloads or OAuth messages, thereby providing access to private data and storage. These attacks can lead to breaches of corporate networks, affecting the trust and transparency of the developer community, making them extremely dangerous.

The investigation into GoIssue reveals a possible link to the Gitloker extortion campaign, as evidence found points to a Telegram of “cyberluffy,” associated with the Gitloker group. This campaign uses GitHub notifications to spread malicious OAuth applications, targeting developer repositories. Researchers note that GoIssue vendors advertise their tools on security blogs, suggesting a possible connection to Gitloker.

GitHub GoIssue

See more: North Korean hackers target macOS systems with Flutter apps

Developers on GitHub should remain vigilant for suspicious emails or messages, as these interactions can be entry points for attacks. The need for proactive security measures is highlighted ashackers use increasingly advanced tools and automation.

Source: darkreading

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS