Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
Operation Muck and Load is a supply chain attack campaign centered on a malicious Go module that impersonates a DNS scanner tool to deliver a multi-stage Windows malware loader. The campaign leverages 222 GitHub lure repositories across 190 accounts with automated commit-farming workflows to create false credibility, and uses public dead-drop resolvers across multiple platforms for resilient payload-location resolution. The final payload chain delivers AsyncRAT, Quasar, Remcos, Vidar infostealer, and cryptominers through password-protected 7z archives extracted into masqueraded Microsoft-themed directories.
- domainmuckcoding[.]comPrimary Muck-themed staging domain; Go module downloads encoded PowerShell payload from this domain as first-stage content
- domainmuckdeveloper[.]comMuck-themed dead-drop resolver domain hosting encrypted payload-location material at /LGTV/MicrosoftCur
- emailischhfd83[@]rambler[.]ruThreat actor-linked email address used in GitHub Actions commit-farming workflows across 222 confirmed lure repositories; key pivot for identifying the broader cluster
- sha256129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bffLayer 1 encrypted PowerShell blob; decrypted with hardcoded 32-byte XOR key
- sha256235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609Confirmed malware sample from threat actor-controlled GitHub repository
- sha2562f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7dConfirmed malware sample from threat actor-controlled GitHub repository
- sha25633497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29Confirmed malware sample from threat actor-controlled GitHub repository
- sha25645126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242Confirmed malware sample from threat actor-controlled GitHub repository
- sha2564ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4SHA-256 of recovered Microsoft.exe launcher extracted from Quixo.7z; executes from masqueraded C:\ProgramData\Windows.Microsoft.Photos\current\ path
- sha25651cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807Encrypted payload-location blob recovered from dead-drop material; decrypted to resolve GitHub release URL
- sha25657e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629Layer 2 encrypted PowerShell blob; uses Base64, XOR, and Invoke-Expression for decryption
- sha25673c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2SHA-256 of recovered Quixo.7z payload archive; password-protected 7z container delivering Electron/Squirrel-style Windows application with RAT payloads
- sha256810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344Confirmed malware sample from threat actor-controlled GitHub repository
- sha25686819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0cLayer 1 decrypted PowerShell script; contains second encrypted PowerShell layer
- sha256938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089Confirmed malware sample from threat actor-controlled GitHub repository
- sha256969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879feSHA-256 of decoded PowerShell stage associated with AsyncRAT, Quasar, and RAT/infostealer-like behavior including persistence, defense evasion, and credential access
- sha2569df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7Confirmed malware sample from threat actor-controlled GitHub repository
- sha256a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7aConfirmed malware sample from threat actor-controlled GitHub repository
- sha256a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4Related GitHub-hosted Quixo.7z sample; maps to Remcos-style RAT activity
- sha256b27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005eConfirmed malware sample from threat actor-controlled GitHub repository
- sha256d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15Confirmed malware sample from threat actor-controlled GitHub repository
- sha256d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1Confirmed malware sample from threat actor-controlled GitHub repository
- sha256e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63Final visible decoded PowerShell loader logic; acts as resolver, downloader, extractor, and launcher
- sha256e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acadConfirmed malware sample from threat actor-controlled GitHub repository
- sha256ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783fConfirmed malware sample from threat actor-controlled GitHub repository
- sha256f245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4Confirmed malware sample from threat actor-controlled GitHub repository
- urlhxxps://docs[.]google[.]com/document/d/1PnogKWvfa3ZcCnmKfnb3pJYXMBmcQe5k_6bBuPUailQ/export?format=txtGoogle Docs dead-drop resolver URL; exports document as text containing encrypted payload-location material
- urlhxxps://gitcode[.]com/LastWer/MicrosoftCur/rawGitCode dead-drop resolver URL; hosts encrypted payload-location material as fallback source
- urlhxxps://github[.]com/AkumaDarks/Exodus-Two-Factor-Authentication-ProtecGitHub lure repository impersonating Exodus 2FA tool; part of 222-repository lure network
- urlhxxps://github[.]com/kaleidora/dnsub-scanning-toolMalicious Go module repository impersonating dnsub DNS scanner; contains embedded Windows malware loader in main.go that launches hidden PowerShell
- urlhxxps://github[.]com/MACv1sh/RaidVortex-Stealer-Discord-FUDGitHub lure repository advertising Discord stealer tool; part of confirmed lure network
- urlhxxps://github[.]com/nrevv1lad/Pubg-DESYNC-MenuMalware-bearing GitHub lure repository posing as PUBG cheat; hosts Loader.exe associated with Vidar infostealer
- urlhxxps://github[.]com/Ohtopusesi2/Metamask-Wallet-Connect-Sdk-Web3-Integration-EthGitHub lure repository impersonating MetaMask WalletConnect SDK; part of lure network targeting crypto users
- urlhxxps://github[.]com/tb78/expresso/releases/download/Release/Quixo[.]7zGitHub release URL resolved by dead-drop resolver; delivers password-protected Quixo.7z payload archive containing Electron-style Windows malware
- urlhxxps://muckcoding[.]com/LG-LW/Api-CertificateFirst-stage download URL; Go module retrieves encoded PowerShell content disguised as certificate artifact, saved locally as api.db
- urlhxxps://muckdeveloper[.]com/LGTV/MicrosoftCurMuck-themed dead-drop resolver URL hosting encrypted payload-location material
- urlhxxps://pastebin[.]com/raw/ULQUekEfAdditional Pastebin dead-drop resolver URL identified in image analysis; hosts encrypted payload-location material with LastW marker
- urlhxxps://pastebin[.]com/raw/xy32SJgfPrimary Pastebin dead-drop resolver URL; hosts encrypted payload-location material marked with 'LastW' string
- urlhxxps://rlim[.]com/MicrosoftCur/rawPrimary Rlim dead-drop resolver URL; hosts encrypted payload-location material for resolving final payload archive URL
- urlhxxps://t[.]me/s/dwmicTelegram dead-drop resolver channel (DwMic); hosts encrypted payload-location material as fallback source
- urlhxxps://www[.]instagram[.]com/p/DG20Zt9Mj4P/Fallback Instagram dead-drop resolver URL; used as recovery path for encrypted payload-location material
- urlhxxps://youtu[.]be/GAS67zAOsscFallback YouTube dead-drop resolver URL; used as recovery path if primary sources are removed
Detection / Hunteropenrouter
What Happened
Researchers discovered a network of fake software projects on GitHub designed to trick people into downloading malware. The operation, called 'Muck and Load,' involves 222 fake repositories across 190 GitHub accounts that use automated systems to make the projects look actively maintained and trustworthy. The attack starts with a malicious Go programming package disguised as a DNS scanning tool, which secretly launches a hidden PowerShell script. That script downloads encrypted instructions from public websites like Pastebin, Telegram, and YouTube to find the real malware. The malware is delivered as a password-protected archive that, when opened, installs remote access tools and password-stealing programs on the victim's computer. Anyone who downloads and runs software from unfamiliar GitHub repositories—especially tools related to cryptocurrency wallets, game cheats, or automation bots—is at risk. Users should verify the authenticity of any open-source package before installing it, and organizations should monitor for unusual PowerShell activity and unexpected file downloads.
Key Takeaways
- A malicious Go module (github.com/kaleidora/dnsub-scanning-tool) impersonating a DNS scanner tool served as the entry point for a multi-stage Windows malware delivery chain
- Operation Muck and Load encompasses 222 confirmed GitHub lure repositories across 190 accounts using automated commit-farming workflows to simulate activity and credibility
- The loader chain uses public dead-drop resolvers (Pastebin, Rlim, Telegram, YouTube, Instagram, Google Docs, GitCode) for resilient payload-location resolution, making takedowns harder
- Final payloads include AsyncRAT, Quasar, Remcos RATs, Vidar infostealer, and XMRig/BitMiner cryptominers, with at least 14 confirmed malware files across GitHub repositories
- Threat actor pivots include email [email protected] used in GitHub Actions commit-farming workflows and Muck-themed domains muckcoding.com and muckdeveloper.com
Affected Systems
- Windows systems targeted by the multi-stage loader chain
- Go module ecosystem (Go module proxy)
- GitHub users and developers who clone or build untrusted repositories
- Developers using Go package management tools
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Malicious Go module (github.com/kaleidora/dnsub-scanning-tool) impersonates dnsub DNS scanner and is distributed via Go module proxy
- Execution: Go module's main.go launches hidden PowerShell to download encoded content from muckcoding.com, saves as api.db, decodes with certutil to L.ps1, and executes with -ExecutionPolicy Bypass
- Defense Evasion: L.ps1 uses multi-layer Base64/XOR encryption with Invoke-Expression across three encrypted layers to recover final resolver logic; disables TLS certificate validation
- C2/Resolver: Final decoded script queries public dead-drop locations (Pastebin, Rlim, Telegram, YouTube, Instagram, Google Docs, GitCode) for encrypted payload-location material marked with 'LastW' string
- Payload Delivery: Resolved URL points to password-protected Quixo.7z on GitHub; archive downloaded, extracted using dropped 7zrr.exe into masqueraded C:\ProgramData\Windows.Microsoft.Photos\ directory
- Impact: Microsoft.exe launches from masquerade path delivering AsyncRAT, Quasar, Remcos, Vidar infostealer with capabilities including credential theft, screen capture, persistence via scheduled tasks and services, and defense evasion via Microsoft Defender/UAC modification
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not provide formal detection rules (YARA, Sigma, Snort, etc.). It provides behavioral indicators, IOCs, and MITRE ATT&CK technique mappings that could be used to build custom detections. A separate GitHub infrastructure appendix with 222 confirmed repositories is published at the Socket threat research IOCs repository.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | The attack chain involves visible process executions (powershell.exe, certutil, 7zrr.exe, Microsoft.exe) and file drops to non-standard paths that EDR should capture. However, the multi-layer encrypted PowerShell and use of living-off-the-land binaries may blend with legitimate activity in some EDR configurations. |
| Network Visibility | Medium | Network connections to muckcoding.com, muckdeveloper.com, and public dead-drop platforms are observable. However, the use of legitimate public platforms (Pastebin, YouTube, Instagram, Telegram, Google Docs) for dead-drop resolution makes network-level blocking difficult without risking false positives on legitimate traffic. |
| Detection Difficulty | Moderate | Individual stages are detectable through behavioral monitoring (hidden PowerShell, certutil decode, masquerade paths), but the resilient dead-drop resolver design across multiple legitimate platforms and the GitHub lure network require broader infrastructure analysis and clustering to fully identify. |
Required Log Sources
- Process creation events (Sysmon Event ID 1 / Windows Security Event ID 4688)
- PowerShell script block logging (Event ID 4104)
- File creation events (Sysmon Event ID 11)
- Network connection events (Sysmon Event ID 3)
- Certificate validation override detection
- GitHub Actions workflow logs
- Go module proxy download logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for PowerShell processes launched with -WindowStyle Hidden and -ExecutionPolicy Bypass flags that subsequently invoke certutil for decoding, as this combination is atypical for legitimate administrative activity. | Sysmon Event ID 1 (process creation), PowerShell Event ID 4104 (script block logging), command-line arguments | Execution / Defense Evasion | Low — legitimate administrative scripts rarely combine hidden window style with certutil decoding and execution policy bypass in sequence. |
| Consider hunting for processes executing from C:\ProgramData\Windows.Microsoft.Photos\ or similar masqueraded Microsoft-themed paths that do not match the legitimate Microsoft Photos installation location. | Sysmon Event ID 1 (process creation), file path monitoring | Persistence / Masquerading | Low — the legitimate Microsoft Photos application does not run from C:\ProgramData\Windows.Microsoft.Photos. |
| If you have visibility into DNS or HTTP logs, consider hunting for systems making sequential connections to multiple public content platforms (Pastebin, Rlim, Telegram, YouTube, Instagram, Google Docs) within a short time window, as this pattern may indicate dead-drop resolver activity. | DNS logs, proxy logs, firewall connection logs | C2 / Dead Drop Resolver | Medium — users legitimately access these platforms; the indicator is the rapid sequential access pattern combined with subsequent archive downloads. |
| Consider hunting for certutil.exe invoked with -decode arguments on files in C:\Users\Public\ or other world-writable directories, as this is a known living-off-the-land technique for payload staging. | Sysmon Event ID 1 (process creation with command line), Sysmon Event ID 11 (file creation) | Defense Evasion / Deobfuscation | Low — certutil -decode is rarely used in legitimate enterprise workflows. |
| If you monitor GitHub activity or use GitHub in your development environment, consider hunting for repositories with GitHub Actions workflows that run every minute, force-push synthetic commits, and use a constant email address across multiple repository owners. | GitHub audit logs, GitHub Actions workflow runs, commit metadata | Infrastructure / Lure Maintenance | Low — legitimate CI/CD workflows do not typically combine every-minute scheduling with force-push of log/timestamp files across many accounts. |
Control Gaps
- Traditional AV signatures may not detect the multi-layer encrypted PowerShell loader since each layer is only decrypted in memory
- Network-level blocking of dead-drop resolver traffic is ineffective without risking blocking legitimate access to Pastebin, YouTube, Telegram, and Google Docs
- GitHub lure repositories with synthetic commit activity may pass automated trust/reputation checks that rely on repository activity metrics
- The use of a signed Electron-style executable (signed by Exodus Movement, Inc.) may bypass application allowlisting that relies on digital signatures
- Password-protected 7z archives may evade content inspection and sandbox detonation at email or web gateways
Key Behavioral Indicators
- PowerShell process launched with -WindowStyle Hidden and -ExecutionPolicy Bypass flags
- certutil.exe invoked with -decode argument on files in C:\Users\Public\ directories
- Process executing from C:\ProgramData\Windows.Microsoft.Photos\current\Microsoft.exe (non-standard Microsoft Photos path)
- 7-Zip extractor binary (7zrr.exe) running from C:\ProgramData\zipathh\ (non-standard path)
- PowerShell script disabling certificate validation via ServerCertificateValidationCallback
- Sequential network connections to multiple public content platforms within short timeframes
- GitHub Actions workflows with every-minute scheduling and force-push of synthetic commits
- Git commit metadata showing constant email address across different repository owner usernames
- Go module with abnormally high version count (1,200+ versions) for a small utility package
False Positive Assessment
Low — the combination of hidden PowerShell execution, certutil decoding, dead-drop resolver queries to multiple public platforms, and execution from masqueraded Microsoft Photos paths is highly specific to this attack chain. Individual indicators (e.g., PowerShell execution, Pastebin access) may generate false positives, but the full behavioral chain is unlikely to appear in legitimate activity.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the domains muckcoding.com and muckdeveloper.com at your DNS filtering or firewall layer if consistent with your policies.
- Consider adding the identified SHA-256 hashes to your EDR or endpoint protection block lists, particularly the Microsoft.exe launcher (4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4) and Quixo.7z archive hash.
- If your organization uses Go, consider verifying whether any developers have imported or referenced the github.com/kaleidora/dnsub-scanning-tool module and review Go module proxy logs for its presence.
- Consider searching your environment for files at C:\Users\Public\Pictures\api.db, C:\Users\Public\Pictures\L.ps1, and C:\ProgramData\Windows.Microsoft.Photos\current\Microsoft.exe as potential compromise indicators.
- If your EDR supports it, consider creating behavioral detection rules for certutil.exe with -decode arguments and PowerShell with -WindowStyle Hidden -ExecutionPolicy Bypass combinations.
Infrastructure Hardening
- Consider implementing allowlisting for Go module imports in your CI/CD pipelines to prevent unauthorized or unvetted packages from being pulled into builds.
- Evaluate whether your web filtering solution can selectively block specific Pastebin, Rlim, and GitCode raw URLs rather than blocking entire domains, to reduce the dead-drop resolver attack surface.
- If your organization uses GitHub, consider monitoring for GitHub Actions workflows with every-minute scheduling and force-push patterns that rewrite log or timestamp files, as these may indicate commit-farming activity.
- Consider implementing network segmentation to restrict development systems from making outbound connections to public content-sharing platforms during build processes.
User Protection
- Consider deploying enhanced PowerShell logging (Script Block Logging, Transcription) across endpoints if not already enabled, to capture the multi-layer decryption chain.
- Evaluate whether your EDR can alert on processes executing from C:\ProgramData\ subdirectories with Microsoft-themed names, as these are non-standard application paths.
- Consider enabling certificate pinning or validation enforcement for critical applications to detect PowerShell scripts that disable certificate validation.
- If applicable, consider deploying application allowlisting that validates both signature and file path, not just signature alone, to catch signed-but-masqueraded executables.
Security Awareness
- Consider adding guidance to existing developer awareness programs about the risks of importing obscure or newly published Go modules, especially those impersonating known tools.
- Consider educating developers and users about the threat of GitHub repositories with artificially inflated activity metrics and how to evaluate repository legitimacy beyond commit frequency.
- Consider incorporating warnings about cryptocurrency-themed, game-cheat, and offensive-tooling lures into existing security awareness training, as these are common social engineering vectors.
- If your organization has developers who use open-source packages, consider promoting the use of package provenance verification tools and dependency scanning in development workflows.
MITRE ATT&CK Mapping
Resource Development
Initial Access
Persistence
Privilege Escalation
Stealth
Defense Impairment
Credential Access
Collection
Command and Control
Impact
Additional IOCs
- Urls:
hxxps://muckcoding[.]com/LG-LW/Api-Certificate- First-stage download URL; Go module retrieves encoded PowerShell content disguised as certificate artifact, saved locally as api.dbhxxps://muckdeveloper[.]com/LGTV/MicrosoftCur- Muck-themed dead-drop resolver URL hosting encrypted payload-location materialhxxps://pastebin[.]com/raw/ULQUekEf- Additional Pastebin dead-drop resolver URL identified in image analysis; hosts encrypted payload-location material with LastW markerhxxps://youtu[.]be/GAS67zAOssc- Fallback YouTube dead-drop resolver URL; used as recovery path if primary sources are removedhxxps://www[.]instagram[.]com/p/DG20Zt9Mj4P/- Fallback Instagram dead-drop resolver URL; used as recovery path for encrypted payload-location materialhxxps://t[.]me/s/dwmic- Telegram dead-drop resolver channel (DwMic); hosts encrypted payload-location material as fallback sourcehxxps://docs[.]google[.]com/document/d/1PnogKWvfa3ZcCnmKfnb3pJYXMBmcQe5k_6bBuPUailQ/export?format=txt- Google Docs dead-drop resolver URL; exports document as text containing encrypted payload-location materialhxxps://gitcode[.]com/LastWer/MicrosoftCur/raw- GitCode dead-drop resolver URL; hosts encrypted payload-location material as fallback sourcehxxps://github[.]com/nrevv1lad/Pubg-DESYNC-Menu- Malware-bearing GitHub lure repository posing as PUBG cheat; hosts Loader.exe associated with Vidar infostealerhxxps://github[.]com/AkumaDarks/Exodus-Two-Factor-Authentication-Protec- GitHub lure repository impersonating Exodus 2FA tool; part of 222-repository lure networkhxxps://github[.]com/Ohtopusesi2/Metamask-Wallet-Connect-Sdk-Web3-Integration-Eth- GitHub lure repository impersonating MetaMask WalletConnect SDK; part of lure network targeting crypto usershxxps://github[.]com/MACv1sh/RaidVortex-Stealer-Discord-FUD- GitHub lure repository advertising Discord stealer tool; part of confirmed lure network
- File Hashes:
129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff(SHA256) - Layer 1 encrypted PowerShell blob; decrypted with hardcoded 32-byte XOR key86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c(SHA256) - Layer 1 decrypted PowerShell script; contains second encrypted PowerShell layer57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629(SHA256) - Layer 2 encrypted PowerShell blob; uses Base64, XOR, and Invoke-Expression for decryptione576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63(SHA256) - Final visible decoded PowerShell loader logic; acts as resolver, downloader, extractor, and launcher51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807(SHA256) - Encrypted payload-location blob recovered from dead-drop material; decrypted to resolve GitHub release URLa628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4(SHA256) - Related GitHub-hosted Quixo.7z sample; maps to Remcos-style RAT activity235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository2f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7d(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository33497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository9df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositorya2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7a(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositoryb27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005e(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositoryd7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositoryd95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositorye73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acad(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositoryec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783f(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repositoryf245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4(SHA256) - Confirmed malware sample from threat actor-controlled GitHub repository
- File Paths:
C:\Users\Public\Pictures\api.db- Attacker-dropped encoded payload file disguised as database; downloaded from muckcoding.com and decoded with certutilC:\Users\Public\Pictures\L.ps1- Attacker-dropped decoded PowerShell loader script; multi-layer encrypted loader with dead-drop resolver logicC:\Users\Public\Documents\umun\- Attacker-created staging directory for Quixo.7z archive downloadC:\ProgramData\zipathh\7zrr.exe- Attacker-dropped 7-Zip command-line extractor used to extract password-protected Quixo.7z archiveC:\ProgramData\Windows.Microsoft.Photos\current\Microsoft.exe- Masqueraded execution path for final payload; mimics legitimate Microsoft Photos application directory
- Command Lines:
- Purpose: Hidden PowerShell execution to download and decode first-stage payload from remote server | Tools:
powershell.exe,Invoke-WebRequest,certutil| Stage: Initial Access / Execution |powershell.exe -WindowStyle Hidden -Command Invoke-WebRequest - Purpose: Decode downloaded encoded content using certutil living-off-the-land technique | Tools:
certutil| Stage: Defense Evasion / Deobfuscation |certutil -decode - Purpose: Execute decoded PowerShell script with execution policy bypass | Tools:
powershell.exe| Stage: Execution |powershell.exe -ExecutionPolicy Bypass - Purpose: GitHub Actions commit-farming workflow to generate synthetic repository activity | Tools:
git,github-push-action| Stage: Infrastructure / Lure Maintenance |git config --local user.email
- Purpose: Hidden PowerShell execution to download and decode first-stage payload from remote server | Tools:
- Other:
LastW- Resolver marker string used to locate encrypted payload-location material in dead-drop contentUIA14fogylw8ogL82FntOFGp6- Hardcoded 32-byte XOR decryption key used to decrypt payload-location blob from dead-drop materialr8NnX1b8Xn- Hardcoded password for extracting Quixo.7z payload archive73hvdu342- Secondary password/string observed in staged activityDirekt calistir, baska adim gerekmez- Turkish-language comment in loader meaning 'Run directly, no other step is needed'CaptureScreens.ps1- Screenshot-collection script name used in post-execution payload activityNvdia- Suspicious misspelling/masquerade string used to impersonate NVIDIA-related components