Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
AI Summary
A malicious Go module, github.com/kaleidora/dnsub-scanning-tool, serves as a lure to deliver a multi-stage Windows malware chain involving hidden PowerShell execution and encrypted payload resolution via public dead drops. The campaign, tracked as Operation Muck and Load, leverages a network of 222 GitHub repositories across 190 accounts to create credibility and scale for malicious or deceptive software projects. These repositories use synthetic activity to appear recently maintained, facilitating social engineering and malware distribution. The final payload includes RATs such as AsyncRAT, Quasar, and Remcos, along with infostealers like Vidar, enabling credential theft, screen capture, and persistence.
AI-extracted · verify before operational use
Extracted Entities 4 found
Indicators of Compromise 23 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | muckcoding[.]com | Details → |
| Domain | muckdeveloper[.]com | Details → |
| Domain | pastebin[.]com | Details → |
| Domain | rlim[.]com | Details → |
| Domain | t[.]me | Details → |
| Domain | gitcode[.]com | Details → |
| Filename | api.db | Details → |
| Filename | L.ps1 | Details → |
| Filename | Microsoft.exe | Details → |
| Filename | 7zrr.exe | Details → |
| SHA-256 | 129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff | Details → |
| SHA-256 | 86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c | Details → |
| SHA-256 | 57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629 | Details → |
| SHA-256 | e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63 | Details → |
| SHA-256 | 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 | Details → |
| SHA-256 | 969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fe | Details → |
| SHA-256 | 73c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2 | Details → |
| SHA-256 | a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4 | Details → |
| SHA-256 | 4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4 | Details → |
| GitHub Repo | github.com/kaleidora/dnsub-scanning-tool | Details → |
| GitHub Repo | github.com/tb78/expresso | Details → |
| GitHub Repo | github.com/LastWer/MicrosoftCur | Details → |
| Registry User | [email protected] | Details → |