Malvertising Campaign Exploits GitHub to Distribute Info-Stealing Malware

A cyberattack disclosed by Microsoft in December compromised nearly one million devices by luring users through illegal streaming sites before redirecting them to malware hosted on GitHub. The campaign used trusted platforms to distribute information-stealing software, highlighting how cybercriminals are exploiting legitimate services to avoid detection and reach both home users and corporate networks.

Nearly one million computers worldwide fell victim to a sprawling cyberattack last month that exploited an unlikely combination: people looking for free movies and the trusted software platform GitHub.

Microsoft’s threat intelligence team disclosed the campaign in December 2024, describing an operation that turned websites hosting pirated content into traps for unsuspecting users. The attack represented a troubling evolution in how cybercriminals distribute malware by hiding in plain sight on legitimate platforms.

The scheme worked like this: Someone searching for a free stream of the latest blockbuster would land on an illegal streaming site. But embedded in those sites were malicious advertisements that quietly redirected visitors through a chain of websites before depositing them on GitHub, where attackers had uploaded software that appeared benign but contained dangerous payloads.

Source: Microsoft.com

Users who downloaded and ran these files handed over access to their computers. The malware quickly got to work cataloging system information and installing additional programs, including Lumma, a tool designed to steal passwords and financial data. The attackers also deployed an updated variant of Doenerium and used NetSupport, a legitimate remote access program typically used by IT departments, to maintain control of infected machines.

The broad targeting meant the campaign hit both home computers and corporate networks across multiple industries. Security researchers say using GitHub complicates detection efforts because the platform hosts millions of legitimate software projects, making it harder for security tools to distinguish between safe and malicious files.

Microsoft did not identify the attackers or specify which countries saw the highest infection rates. The company’s disclosure comes as cybersecurity experts have grown increasingly concerned about malvertising, a technique that has proven effective because it requires no special action from victims beyond visiting a compromised website.

For users, the incident offers a reminder that piracy sites carry risks beyond legal trouble. Security experts recommend sticking to legitimate streaming services and keeping antivirus software up to date. Organizations should block access to known piracy domains on corporate networks and train employees to recognize suspicious download requests.

The attackers’ decision to weaponize GitHub highlights how cybercriminals adapt their methods to exploit trust in widely used platforms, making traditional security approaches less effective.

Recommendations and Mitigation

To mitigate the risks associated with such attacks, organizations and individuals are advised to:

  • Exercise Caution: Avoid visiting illegal streaming sites or downloading content from untrusted sources.
  • Implement Security Measures: Use reputable security software and ensure it is regularly updated to detect and prevent malware.
  • Educate Users: Conduct regular training sessions to raise awareness about the dangers of malvertising and the importance of safe browsing habits.

By staying vigilant and adopting proactive security practices, users can protect themselves against such sophisticated cyber threats.

For corrections, news tips, and any other content requests, please send us an email at [email protected].

Hot this week

Here is What You Need to Know Why “Sidewalk Ban” Faces Backlash

The sidewalk ban ordinance in Albuquerque has raised concerns over people facing homelessness. Here is what you need to know.

Soaring Housing Costs Push Santa Fe Police Into Rio Rancho

Santa Fe police officers are increasingly living in Rio Rancho due to soaring housing costs, raising concerns about community connection and public safety.

Police: 4 Men Plotted Deadly Ambush Near UNM

A fatal shooting near the University of New Mexico campus is being investigated as a possible planned ambush after four suspects were taken into custody in the killing of 23-year-old Eden Rock. Police say surveillance footage showed the men hiding behind a dumpster before attacking and shooting the victim in an alley south of Central Avenue.

Sip, Savor, Celebrate, and More —Cocktail Week Takes Over New Mexico

New Mexico Cocktail Week returns for its fourth year, highlighting the state’s growing craft cocktail scene with events, tastings, and a shift toward mocktails.

APS Superintendent Honors Graduates: ‘Make the World a Better Place’

In her weekly message, Albuquerque Public Schools Superintendent Gabriella Durán Blakey recognized Class of 2026 graduates and thanked those behind their success.

Topics

Here is What You Need to Know Why “Sidewalk Ban” Faces Backlash

The sidewalk ban ordinance in Albuquerque has raised concerns over people facing homelessness. Here is what you need to know.

Soaring Housing Costs Push Santa Fe Police Into Rio Rancho

Santa Fe police officers are increasingly living in Rio Rancho due to soaring housing costs, raising concerns about community connection and public safety.

Police: 4 Men Plotted Deadly Ambush Near UNM

A fatal shooting near the University of New Mexico campus is being investigated as a possible planned ambush after four suspects were taken into custody in the killing of 23-year-old Eden Rock. Police say surveillance footage showed the men hiding behind a dumpster before attacking and shooting the victim in an alley south of Central Avenue.

Sip, Savor, Celebrate, and More —Cocktail Week Takes Over New Mexico

New Mexico Cocktail Week returns for its fourth year, highlighting the state’s growing craft cocktail scene with events, tastings, and a shift toward mocktails.

APS Superintendent Honors Graduates: ‘Make the World a Better Place’

In her weekly message, Albuquerque Public Schools Superintendent Gabriella Durán Blakey recognized Class of 2026 graduates and thanked those behind their success.

Las Cruces Catholic Diocese Pushes Back Against Border Wall Land Grab That Threatens Sacred Mount Cristo Rey

The U.S. government is seeking to seize land owned by the Roman Catholic Diocese of Las Cruces for border wall construction near Mount Cristo Rey, a revered pilgrimage site in southern New Mexico. The diocese argues the move violates religious freedom protections and threatens access to sacred ground visited by thousands each year.

Officials and U.S. Air Force Agree on PFAS Cleanup Plan at Cannon

In New Mexico, environmental officials have reached an agreement...

Agencies Focus on Outreach as Screwworm Threat Approaches

New Mexico agencies are focusing on outreach as the New World screwworm approaches, raising concerns among ranchers about livestock health and economic impacts. This headline matters because the screwworm, eradicated from the U.S. decades ago, has resurged in Mexico and threatens to cross the border.

Related Articles