216.73.216.40

Hiding in GitHub

· Published 20/06/2025 19:25 · Modified 23/06/2025 23:09

Export JSON

Essential information

Published
20/06/2025 19:25
Modified
23/06/2025 23:09
Tags
2025-06-20 amos cryptocurrency github hardware-wallet ledger macos obfuscation stealer
Related entities
4 observables, 1 intrusion sets (apt)

Description

An malware campaign has been discovered utilizing repositories to distribute malicious files. The attackers created a fake Live app that prompts users to enter their secret phrases, which are then exfiltrated. The malware uses techniques, including base64 encoding and custom XOR operations. The campaign targets users, specifically those using hardware wallets. The malware is distributed through DMG files and ZIP archives, containing both x64 and ARM64 versions of . The attackers use multiple domains for command and control, and the malware performs checks to detect virtual environments.

External references