Tag Archive for: GitHub

Gitpaste-12: A dozen exploits that silently lived on GitHub, attacked Linux servers


Just months after Octopus Scanner was caught infecting 26 open-source projects on GitHub, new reports have already surfaced of another, new sophisticated malware infection. Gitpaste-12, a worming botnet, is extremely versatile in its advanced capabilities and the fact it leverages trustworthy sites like GitHub and Pastebin to host itself.

The name Gitpaste-12 stems from the 12 known vulnerability exploits within the worm, much like a “swiss-army knife.” Two of these exploits target 2 popular open source components, Apache Struts and mongoDB.

Remained undetected on GitHub for over 3 months

By hosting its malicious payload on sites like GitHub and Pastebin, the Command and Control (C2) infrastructure now becomes incredibly hard to block using simple IOC-blocks at enterprises, because there are legitimate use-cases of these websites.

In fact, Gitpaste-12 has been silently sitting on GitHub since July 2020.

Gitpaste1

It wasn’t until Juniper Threat Labs spotted the botnet on October 15th, and had GitHub shut it down roughly two weeks later.

“The malware begins by preparing the environment. This means stripping the system of its defenses, including firewall rules, selinux, apparmor, as well as common attack prevention and monitoring software,” said Juniper Threat Labs researchers Alex Burt and Trevor Pott.

Gitpaste2

The worm provides attackers reverse shells. The researchers observed some infected systems using TCP ports 30004 and 30005 open to listen for shell commands.

Furthermore, Gitpaste-12 is loaded with a Monero cryptocurrency miner with additional code to hide it from process monitors, a Telnet-based script to breach Linux servers, and IoT devices via brute force, a cronjob that paves way for the worm to gain persistence, and so on.

“The Gitpaste-12 malware also contains a script that launches attacks against other machines, in an attempt to replicate and spread. It chooses a random /8 CIDR for attack and will try (Read more…)

Source…

Botnet Operators Abusing Legit GitHub, Pastebin Resources


Cryptocurrency Fraud
,
Cybercrime
,
Fraud Management & Cybercrime

Researchers: ‘Gitpaste-12’ Botnet Mainly Targets Linux And IoT Devices

Botnet Operators Abusing Legit GitHub, Pastebin Resources
GitHub Page Hosting ‘Gitpaste-12’ malware before being taken down (Source: Juniper Threat Labs)

The operators behind a recently uncovered botnet dubbed “Gitpaste-12” are abusing legitimate services such as GitHub and Pastebin to help hide the malware’s malicious infrastructure, according to report from Juniper Threat Labs.

See Also: Palo Alto Networks Ignite 20: Discover the Future of Cybersecurity, Today


The botnet, which was first uncovered in October but appears to have been activated in July, mainly targets vulnerable Linux applications as well as internet of things and other connected devices, according to Juniper. The researchers also note that the malware contains at least 12 separate attack modules to help it infect new endpoints and apps.


While the ultimate purpose of the botnet is not fully known, the Juniper analysis finds that Gitpaste-12 comes equipped with cryptomining capabilities and can specifically mine monero cryptocurrency, according to the report.


It is the use of legitimate services such as Pastebin and Github, however, that stood out when the researchers first came across the botnet last month, according to the report.


By using Pastebin and GitHub, the malware can remain hidden from firewalls and proxies. This allows the operators to act stealthily while building the botnet and sending instructions through the command-and-control server, according Juniper’s Alex Burt and Trevor Pott note in their report.


Juniper has contacted…

Source…

Malware Attack on GitHub Repositories a Disturbing Development for Open Source Projects – CPO Magazine

Malware Attack on GitHub Repositories a Disturbing Development for Open Source Projects  CPO Magazine
“malware news” – read more

Cyber Security Today – A new ransomware threat, a warning for GitHub users and Apple security updates. – IT World Canada

Cyber Security Today – A new ransomware threat, a warning for GitHub users and Apple security updates.  IT World Canada
“computer security news” – read more