GitHub repositories targeted in cyber-extortion attacks

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

GitHub Extortion Campaign: “Gitloker” Wiping Clean Repositories

An unknown user operating under the alias “Gitloker” has been wreaking havoc on GitHub by seizing and erasing repositories in an effort to extort victims. The campaign, brought to light by a researcher at Chilean cybersecurity firm CronUp, has been ongoing since at least February 2024. Reports from GitHub community forums suggest that multiple users have fallen victim to this scheme, although the full extent of the attacks remains unknown.

According to CronUp researcher German Fernandez, the attackers are exploiting a GitHub commenting and notification feature to carry out their phishing emails. By utilizing the legitimate “notifications@github.com” email address and manipulating sender names, the attackers have been successful in luring victims into their trap. The campaign operates through two domains: “githubcareers.online” and “githubtalentcommunity.online.”

One victim described how the attacker uploaded repos to their account and left behind an extortion note demanding $1,000 to prevent data exposure. Other users reported receiving fake recruiting emails and security alerts, all leading to the same malicious domains. GitHub has advised users to review their active sessions, personal access tokens, change passwords, and reset two-factor recovery codes if they suspect their account has been compromised.

The implications of Gitloker’s actions are dire, as some victims have been threatened with the release of confidential data unless a hefty ransom is paid. GitHub has assured users that they are investigating all reports of abusive activity and encourages the community to report any suspicious behavior. As the cybersecurity battle on GitHub intensifies, vigilance and proactive measures are crucial to safeguarding sensitive information.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Ubuntu Releases Security Updates for FFmpeg Vulnerabilities Across Multiple LTS Versions

Ubuntu Security Updates Address FFmpeg Vulnerabilities Across Multiple LTS Versions Ubuntu has released critical security updates for the FFmpeg multimedia framework, addressing vulnerabilities across several...

Ukraine Grants Britain Access to Battlefield Data for AI Training in Defense Partnership

Ukraine has agreed to provide Britain with access to extensive battlefield data collected during its ongoing conflict with Russia. This partnership will enable U.K....

Supply Chain Attacks Target Developer Tools and CI/CD Pipelines, Research Reveals

In recent years, supply chain attacks have evolved dramatically, shifting from targeting finished software to infiltrating the very tools and code that developers use...

NordVPN Alerts Android Users to Malware Posing as Ryanair, Emirates, and Qatar Airways Apps

NordVPN has issued a warning to Android users about a sophisticated malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar...