Malware News Fake LDAPNightmware exploit on GitHub spreads infostealer malware

Captain Awesome

Level 26
Thread author
Verified
Top Poster
Well-known
May 7, 2016
1,560
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.

The tactic isn't novel, as there have been multiple documented cases of malicious tools disguised as PoC exploits on GitHub.
 

bazang

Level 12
Jul 3, 2024
551
New words and phrases:
  • Repo Stars (equivalent to Likes)
  • Growth Hacking (pumping up the Repo stars to attract funding and people to the Repo)
  • Fake Star Attacks (non-legitimate methods used to increase the Repo star count)
In short, it is the age-old proven method of social engineering people with Stars/Likes because people are users that want to use stuff. Predictable.

Why do the threat actors target GitHub and GitLab? Because they are the most popular and visited. Predictable.
 
  • Like
Reactions: Jack

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top