GitHub Used as Covert Channel in Multi-Stage Malware Campaign (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- LNK files as initial vector
- GitHub repository for C2 communication
- PowerShell scripts for persistence and exfiltration
"A new multi-stage malware campaign uses LNK files to establish C2 via GitHub, leveraging embedded decoders and PowerShell for persistence and data exfiltration. This technique evades traditional network detection by abusing legitimate GitHub services."
no comments yet.