Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Home/BOTNET, Compromised, Internet Security, Security Advisory, Security Update, Zero Day Attack/Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Researchers detected fake company accounts on GitHub linked to a deceitful cybersecurity company. These accounts are promoting harmful repositories on the code hosting service.

These malicious exploits are promoted by purported researchers from a bogus cybersecurity company called “High Sierra Cyber ​​Security,” who promote GitHub repositories on Twitter, likely targeting cybersecurity researchers and companies involved in vulnerability research.

This campaign was discovered by VulnCheck, which reports that it has been running since at least May 2023, promoting alleged exploits for zero-day flaws in popular software such as Chrome, the Discord, the Signal, WhatsApp and Microsoft Exchange.

The threat actors behind the campaign are also unknown, but they seem persistent, creating new profiles and repositories every time existing ones get flagged and deleted.

The choice of the appropriate file is contingent upon the operating system currently in place. As here, both Linux and Windows  users get the same file but with different names that we have mentioned below:-

  • Linux users: ‘cveslinux.zip’
  • Windows users: ‘cveswindows.zip’

Overall, at the time of writing, the threat actors have the following seven malicious repositories on Github that you shouldn’t touch with a ten-foot pole. 

  • github.com/AKuzmanHSCS/Microsoft-Exchange-RCE
  • github.com/BAdithyaHSCS/Exchange-0-Day
  • github.com/DLandonHSCS/Discord-RCE
  • github.com/GSandersonHSCS/discord-0-day-fix
  • github.com/MHadzicHSCS/Chrome-0-day
  • github.com/RShahHSCS/Discord-0-Day-Exploit
  • github.com/SsankkarHSCS/Chromium-0-Day

‍Follow Us on: Twitter, InstagramFacebook to get the latest security news!

By | 2023-06-16T07:11:14+05:30 June 15th, 2023|BOTNET, Compromised, Internet Security, Security Advisory, Security Update, Zero Day Attack|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!