Fake zero-day PoC exploits on GitHub push Windows, Linux malware

https://www.bleepingcomputer.com/news/security/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware/

Someone created a bunch of github profiles impersonating real researchers alongside fake Twitter accounts. Pretty fascinating, really.

10 points · 3 comments · view on lemmy.world

3 Comments

ambystoma@feddit.de · 2 pts · 3y (1 reply)

huh, this is weird. one would think people would use separate machines / vms to test zero day exploits, not their main machines.

execveat@infosec.pub · 4 pts · 3y

They're not even that stealthy. The code is bullshit, gitignore folder is super suspicious and malware is just a binary within the zip file. Clearly meant for script kiddies.

SHITPOSTING_ACCOUNT@feddit.de · 1 pts · 3y

Any attribution?