BTC $54891.0445
ETH $2430.7119
BNB $478.9820
SOL $139.4463
XRP $0.5044
stETH $2451.8350
DOGE $0.0960
TON $5.4733
ADA $0.3238
TRX $0.1226
wstETH $2848.6399
WBTC $55007.2397
AVAX $20.4645
WETH $2451.5210
DOT $4.3374
LINK $9.8700
BCH $313.6076
DAI $0.9934
UNI $5.6345
LTC $57.1293
BSC-USD $1.0021
MATIC $0.4012
KAS $0.1620
weETH $2540.3720
I***** $7.3435
PEPE $0.0000
USDE $0.9969
XMR $148.6638
ETC $17.8959
CAKE $1.4660
APT $5.1448
IMX $1.1158
NEAR $3.5800
FET $0.8413
OKB $33.4153
FDUSD $0.9911
MNT $0.6016
FIL $3.4036
HBAR $0.0541
STX $1.2845
WBT $10.1102
RNDR $4.6267
XLM $0.0894
VET $0.0222
TAO $250.0656
MKR $1914.3417
ENS $17.1297
BTC $54891.0445
ETH $2430.7119
BNB $478.9820
SOL $139.4463
XRP $0.5044
stETH $2451.8350
DOGE $0.0960
TON $5.4733
ADA $0.3238
TRX $0.1226
wstETH $2848.6399
WBTC $55007.2397
AVAX $20.4645
WETH $2451.5210
DOT $4.3374
LINK $9.8700
BCH $313.6076
DAI $0.9934
UNI $5.6345
LTC $57.1293
BSC-USD $1.0021
MATIC $0.4012
KAS $0.1620
weETH $2540.3720
I***** $7.3435
PEPE $0.0000
USDE $0.9969
XMR $148.6638
ETC $17.8959
CAKE $1.4660
APT $5.1448
IMX $1.1158
NEAR $3.5800
FET $0.8413
OKB $33.4153
FDUSD $0.9911
MNT $0.6016
FIL $3.4036
HBAR $0.0541
STX $1.2845
WBT $10.1102
RNDR $4.6267
XLM $0.0894
VET $0.0222
TAO $250.0656
MKR $1914.3417
ENS $17.1297
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • Global scam by Stargazer Goblin: 3,000 fake GitHub accounts spreading malware

    The attacker, Stargazer Goblin, created a network of counterfeit GitHub accounts to distribute various malware. The scheme, which has generated $100,000 in illicit profits over the past year, includes more than 3,000 accounts used to host malicious links and software.

    The fraudulent “Stargazers Ghost Network,” named by Check Point, encompasses thousands of repositories hosting malware such as Atlantida Stealer, Rhadamanthys, RisePro, Lumma Stealer, and RedLine. These accounts are also involved in various activities on the platform to give them the appearance of legitimacy.

    The network's activities were detected in August 2022, but ads for the scheme appeared on the Dark Net only in early July 2023. According to experts, the network not only spreads malware but also performs other tasks to make these fake accounts look like regular users.

    To protect against being taken off the platform, Stargazer Goblin uses different categories of accounts for different aspects of the scheme. Some accounts create phishing repository templates, others host images for these templates, and still others add malware in the form of password-protected archives disguised as cracked software and game cheats.

    As GitHub accounts are detected and blocked, Stargazer Goblin updates links to new active malware releases, ensuring minimal disruption to operations. Some accounts in the network were previously compromised, and their credentials were likely obtained by ransomware.

    The Stargazer Ghost Network shows a high level of organization and adaptability, which allows attackers to minimize losses and quickly recover from GitHub's actions. Using different accounts for different tasks makes their infrastructure resistant to detection and removal from the platform.

    This case highlights the importance of international law enforcement cooperation in the fight against cybercrime and demonstrates how even the most influential dark web markets can be stopped.

    Comments 0

    Add comment