Malvertising Campaign Exploits GitHub to Distribute Info-Stealing Malware

A cyberattack disclosed by Microsoft in December compromised nearly one million devices by luring users through illegal streaming sites before redirecting them to malware hosted on GitHub. The campaign used trusted platforms to distribute information-stealing software, highlighting how cybercriminals are exploiting legitimate services to avoid detection and reach both home users and corporate networks.

Nearly one million computers worldwide fell victim to a sprawling cyberattack last month that exploited an unlikely combination: people looking for free movies and the trusted software platform GitHub.

Microsoft’s threat intelligence team disclosed the campaign in December 2024, describing an operation that turned websites hosting pirated content into traps for unsuspecting users. The attack represented a troubling evolution in how cybercriminals distribute malware by hiding in plain sight on legitimate platforms.

The scheme worked like this: Someone searching for a free stream of the latest blockbuster would land on an illegal streaming site. But embedded in those sites were malicious advertisements that quietly redirected visitors through a chain of websites before depositing them on GitHub, where attackers had uploaded software that appeared benign but contained dangerous payloads.

Source: Microsoft.com

Users who downloaded and ran these files handed over access to their computers. The malware quickly got to work cataloging system information and installing additional programs, including Lumma, a tool designed to steal passwords and financial data. The attackers also deployed an updated variant of Doenerium and used NetSupport, a legitimate remote access program typically used by IT departments, to maintain control of infected machines.

The broad targeting meant the campaign hit both home computers and corporate networks across multiple industries. Security researchers say using GitHub complicates detection efforts because the platform hosts millions of legitimate software projects, making it harder for security tools to distinguish between safe and malicious files.

Microsoft did not identify the attackers or specify which countries saw the highest infection rates. The company’s disclosure comes as cybersecurity experts have grown increasingly concerned about malvertising, a technique that has proven effective because it requires no special action from victims beyond visiting a compromised website.

For users, the incident offers a reminder that piracy sites carry risks beyond legal trouble. Security experts recommend sticking to legitimate streaming services and keeping antivirus software up to date. Organizations should block access to known piracy domains on corporate networks and train employees to recognize suspicious download requests.

The attackers’ decision to weaponize GitHub highlights how cybercriminals adapt their methods to exploit trust in widely used platforms, making traditional security approaches less effective.

Recommendations and Mitigation

To mitigate the risks associated with such attacks, organizations and individuals are advised to:

  • Exercise Caution: Avoid visiting illegal streaming sites or downloading content from untrusted sources.
  • Implement Security Measures: Use reputable security software and ensure it is regularly updated to detect and prevent malware.
  • Educate Users: Conduct regular training sessions to raise awareness about the dangers of malvertising and the importance of safe browsing habits.

By staying vigilant and adopting proactive security practices, users can protect themselves against such sophisticated cyber threats.

For corrections, news tips, and any other content requests, please send us an email at info@brant.one.

Hot this week

Nearly 3,000 Workers Train for Climate, Infrastructure Jobs as Clean Energy and Public Works Projects Ramp Up

The New Mexico Department of Workforce Solutions says 2,800 workers have completed training for climate-ready and infrastructure careers, surpassing earlier targets as the state prepares for a surge in clean energy and public works projects.

Job Right Out of High School? CEC Helps Make This Possible for Students

The Career Enrichment Center (CEC) helps prepare students for hands-on careers in their chosen fields.

Serving NMSU and the Community, Student Broadcasters Earn National Recognition

New Mexico University’s (NMSU) student broadcasters at KRUX 91.5 FM recently earned national recognition.

Jobless Claims Dipped —US Filings Edged Up to 212K

New Mexico records a slight dip in new unemployment claims even as nationwide filings inch up, signaling mixed labor market trends.

Seeking To Boost Your Spreadsheet Skills? This Training Series Has You Covered

New Mexico State University and NM EDGE collaborate to help individuals expand their spreadsheet skills through a practical training series.

Topics

Nearly 3,000 Workers Train for Climate, Infrastructure Jobs as Clean Energy and Public Works Projects Ramp Up

The New Mexico Department of Workforce Solutions says 2,800 workers have completed training for climate-ready and infrastructure careers, surpassing earlier targets as the state prepares for a surge in clean energy and public works projects.

Job Right Out of High School? CEC Helps Make This Possible for Students

The Career Enrichment Center (CEC) helps prepare students for hands-on careers in their chosen fields.

Serving NMSU and the Community, Student Broadcasters Earn National Recognition

New Mexico University’s (NMSU) student broadcasters at KRUX 91.5 FM recently earned national recognition.

Jobless Claims Dipped —US Filings Edged Up to 212K

New Mexico records a slight dip in new unemployment claims even as nationwide filings inch up, signaling mixed labor market trends.

Seeking To Boost Your Spreadsheet Skills? This Training Series Has You Covered

New Mexico State University and NM EDGE collaborate to help individuals expand their spreadsheet skills through a practical training series.

Celebrating Black History: UNM’s New AFRO Hair Shop Opens Its Doors

The AFRO Hair Shop recently opened at the University of New Mexico, offering a welcoming and inclusive environment for customers.

Residency Lawsuit Against Duke Rodriguez Dismissed. He’s Still in the NM Governor’s Race.

A Santa Fe judge threw out a lawsuit questioning Duke Rodriguez’s residency, the second court dismissal of challenges to his 2026 gubernatorial bid.

APS Reports Rising Graduation Rates for Class of 2025, Two Schools Exits MRI Status

Albuquerque Public Schools (APS) said that 12 of its 20 high schools increased graduation rates.

Related Articles