Hackers Use Github For Malware

Hackers Use Github For Malware

Source: YouTube · John Hammond · published Apr 23, 2024 · 20:46

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video explores the "Living off Trusted Sites" (LOTS) project, specifically demonstrating how attackers can abuse GitHub's features for command and control (C2) to evade detection 0:00.

Key Takeaways:
• The LOTS project catalogs legitimate websites exploitable for phishing, exfiltration, and C2 to bypass security filters, with GitHub being a prime target 0:46.
• Malicious actors can drag and drop files into GitHub issues to generate public URLs under the repository owner's domain, creating false attribution 5:33.
• Real-world malware families like "Smart Loader" have utilized this GitHub flaw to distribute payloads via URLs appearing to belong to Microsoft 8:35.
• The host demonstrates a proof of concept using GitHub Releases to hide encrypted C2 traffic, making it indistinguishable from legitimate software updates aside from rapid timestamps 14:34.

Ultimately, leveraging trusted sites like GitHub for covert operations poses a significant detection challenge for security professionals 20:05.

Sources:

  • 0:00 Introduction to LOTS and GitHub C2
  • 0:46 Living off trusted sites explanation
  • 5:33 GitHub issue file upload technique
  • 8:35 Real-world malware abuse via BleepingComputer article
  • 14:34 GitHub Releases C2 proof of concept
  • 20:05 Summary of detection difficulties

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

this website cataloges and archives a list of other websites that could be used and abused by hackers and I mean both kinds of hackers here the good and the bad cyber criminals threat actors and adversaries and security researchers or penetration testers red teamers and ethical hackers this is the living off trusted sites or Lots project put together by Mr docks if you aren't familiar Mr Doc is an incredible individual doing sweet security research and sharing a whole lot of Education just as well and this might be very similar if you're used to other websites like lbass or GTFO bins living off the land techniques or using natural native inherent capabilities that might allow you to break out of an environment or do something with a little bit more tradecraft in this case living off truste…