Over 3,000 GitHub accounts used by malware distribution service

Share:

Threat actors known as ‘Stargazer Goblin’ have created a malware Distribution-as-a-Service (DaaS) from over 3,000 fake accounts on GitHub that push information-stealing malware.

The malware delivery service is called Stargazers Ghost Network and it utilizes GitHub repositories along with compromised WordPress sites to distribute password-protected archives that contain malware. In most cases, the malware are infostealers, such as RedLine, Lumma Stealer, Rhadamanthys, RisePro, and Atlantida Stealer.

Due to GitHub being a well-known, trusted service, people treat it with less suspicion and may be more likely to click on links they find in the service’s repositories.

Check Point Research discovered the operation, which says it is the first time that such an organized and large-scale scheme has been documented running on GitHub.

“The campaigns performed by the Stargazers Ghost Network and malware distributed via this service are extremely successful,” explains the report by Check Point Research.

“In a short period of time, thousands of victims installed software from what appears to be a legitimate repository without suspecting any malicious intent. The heavily victim-oriented phishing templates allow threat actors to infect victims with specific profiles and online accounts, making the infections even more valuable.”

GitHub ‘ghosts’ spreading malware

The creator of the DaaS operation, Stargazer Goblin, has been actively promoting the malware distribution service on the dark web since June 2023. However, Check Point says there’s evidence it has been active since August 2022.

Stargazer Goblin established a system where they create hundreds of repositories using three thousand fake ‘ghost’ accounts. These accounts star, fork, and subscribe to malicious repositories to increase their apparent legitimacy and make them more likely to appear on GitHub’s trending section.

The repositories use project names and tags that target specific interests like cryptocurrency, gaming, and social media.

The ‘ghost’ accounts are assigned distinct roles. One group serves the phishing template, another provides the phishing image, and a third serves the malware, which gives the scheme a certain level of operational resilience.

“The third account, which serves the malware, is more likely to be detected. When this happens, GitHub bans the entire account, repository, and associated releases,” explains researcher Antonis Terefos.

“In response to such actions, Stargazer Goblin updates the first account’s phishing repository with a new link to a new active malicious release. This allows the network to continue operating with minimum losses when a malware-serving account is banned.”

Check Point has observed a case of a YouTube video with a software tutorial linking to the same operative as in one of the ‘Stargazers Ghost Network’ GitHub repositories.

The researchers note that it could be one of the potentially multiple examples of channels used to funnel traffic to phishing repositories or malware distribution sites.

In terms of the size of the operation and its profit generation, Check Point estimates that the threat actor has made over $100,000 since the service’s launch.

As for what malware is distributed through the Stargazers Ghost Network’s operation, Check Point says it includes RedLine, Lumma Stealer, Rhadamanthys, RisePro, and Atlantida Stealer, among others.

In one example attack chain presented in Check Point’s report, the GitHub repository redirects visitors to a compromised WordPress site, from where they download a ZIP archive containing an HTA file with VBScript.

The VBScript triggers the execution of two successive PowerShell scripts that ultimately lead to the deployment of the Atlantida Stealer.

Although GitHub has taken action against many of the malicious and essentially fake repositories, taking down over 1,500 since May 2024, Check Point says that over 200 are currently active and continue to distribute malware.

Users arriving on GitHub repositories through malvertising, Google Search results, YouTube videos, Telegram, or social media are advised to be very cautious with file downloads and the URLs they click.

This is especially true of password-protected archives, which cannot be scanned by antivirus software. For these types of files, it is suggested you extract them on a VM and scan the extracted contents with antivirus software to check for malware.

If a virtual machine is not available, you can also use VirusTotal, which will prompt for the password of a protected archive so it can scan its contents. However, VirusTotal can only scan a protected archive if it contains a single file.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:31 pm, Jun 22, 2025
weather icon 25°C
L: 24° | H: 27°
few clouds
Humidity: 49 %
Pressure: 1014 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 25°°C 0 mm 0% 15 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 23°°C 0 mm 0% 17 mph 48 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,045.12
-1.22%
Ethereum(ETH)
€1,972.48
-6.95%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.77
-4.85%
Solana(SOL)
€115.81
-6.21%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.135135
-4.88%
Shiba Inu(SHIB)
€0.000010
-4.77%
Pepe(PEPE)
€0.000008
-8.63%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top