Get All Access for $5/mo

New Malware Campaign Targets Finance and Insurance Sectors Using GitHub Links In India, there are currently 13.2 million developers using GitHub, also ranks second globally, after the US, in the number of GenAI projects hosted on GitHub

By Entrepreneur Staff

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Freepik

A new cyberattack campaign targeting the finance and insurance industries is leveraging GitHub links to bypass security measures and deliver malware, according to recent findings by cybersecurity firm Cofense. The campaign uses phishing emails that contain links to trusted GitHub repositories, tricking recipients into downloading a dangerous Remote Access Trojan (RAT) called Remcos.

This technique stands out because the attackers are using legitimate open-source repositories like UsTaxes, HMRC, and InlandRevenue, rather than the usual suspicious or low-star GitHub repositories. Jacob Malimban, a researcher at Cofense, noted that this is a shift from the traditional methods, where threat actors create their own malicious GitHub repositories.

The attack abuses GitHub's infrastructure by uploading malicious files as comments in well-known repositories. Once uploaded, the comment is deleted, but the link to the malware file remains active. This method, first discovered by OALABS Research earlier this year, leaves little trace, making it difficult for security teams to detect the threat.

"Emails containing links to GitHub are effective at bypassing email security systems because GitHub is a trusted domain," said Malimban. Attackers use these links to deliver the malware archive directly through email, avoiding other methods like QR codes or Google redirects.

This is not the only new tactic observed in recent phishing attacks. Barracuda Networks has reported other innovative methods used by cybercriminals, such as ASCII- and Unicode-based QR codes and blob URLs. These tactics make it more challenging for security systems to block malicious content.

A blob URL, as explained by security researcher Ashitosh Deshnur, is a type of link used by web browsers to handle binary data like files or images directly in the browser, bypassing the need for external servers. This tactic gives attackers another way to deliver harmful content undetected.

Additionally, cybersecurity firm ESET has uncovered new scams targeting popular accommodation booking platforms like Booking.com and Airbnb. Scammers are using compromised accounts of legitimate hotels to contact customers, asking them to resolve fake payment issues by clicking on malicious links. The rise in such attacks was noted in July 2024, with attackers focusing on customers who had recently booked or made payments.

The group behind these booking scams, known as Telekopye, has also improved its toolkit by automating the creation of phishing pages and using chatbots to communicate with victims. Despite the sophistication of these scams, law enforcement agencies in Czechia and Ukraine arrested several members of the group in late 2023. Authorities revealed that the criminals recruited individuals in difficult life situations, offering them "easy money" for assisting in these schemes.

As these attacks become more creative and harder to detect, businesses in the finance, insurance, and hospitality sectors need to remain vigilant and adopt stronger cybersecurity measures to protect their systems and customers.

In India, there are currently 13.2 million developers using GitHub, compared to approximately 20 million in the US. India also ranks second globally, after the US, in the number of generative artificial intelligence (genAI) projects hosted on GitHub.

Entrepreneur Staff

Entrepreneur Staff

Editor

For more than 30 years, Entrepreneur has set the course for success for millions of entrepreneurs and small business owners. We'll teach you the secrets of the winners and give you exactly what you need to lay the groundwork for success.
Business News

'Jaw-Dropping Performance in 2024,' Says a Senior Analyst as Nvidia Reports Earnings

Nvidia reported its highly-anticipated third-quarter earnings on Wednesday.

Business News

'Do You Sell Cars?': Tesla CEO Elon Musk Trolls Jaguar Rebrand on X

The team running Jaguar's X account was working hard on social media this week.

Starting a Business

He Started a Business That Surpassed $100 Million in Under 3 Years: 'Consistent Revenue Right Out of the Gate'

Ryan Close, founder and CEO of Bartesian, had run a few small businesses on the side — but none of them excited him as much as the idea for a home cocktail machine.

Employee Experience & Recruiting

Avoid Costly Hiring Mistakes by Spotting These Employee Warning Signs

Hiring is an art, not a science — especially today, with computer-generated résumés, an extremely diverse candidate pool, and decreasing employee loyalty. Here are some tips for how to zero in on the right applicants, with equal parts caution and consideration.

Money & Finance

5 Links You Need to Be Successful As a Day Trader

Mastering drive, computer skills, emotional regulation, situational awareness and discipline are essential for day trading success.

Business News

'Unexpected Funding': Paychex's Founder Donates $85 Million to 41 Nonprofits. Here's Where the Money Is Going.

Paychex founder Tom Golisano has given half a billion dollars to philanthropic causes this year alone.