New Malware Campaign Targets Finance and Insurance Sectors Using GitHub Links In India, there are currently 13.2 million developers using GitHub, also ranks second globally, after the US, in the number of GenAI projects hosted on GitHub

By Entrepreneur Staff

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Freepik

A new cyberattack campaign targeting the finance and insurance industries is leveraging GitHub links to bypass security measures and deliver malware, according to recent findings by cybersecurity firm Cofense. The campaign uses phishing emails that contain links to trusted GitHub repositories, tricking recipients into downloading a dangerous Remote Access Trojan (RAT) called Remcos.

This technique stands out because the attackers are using legitimate open-source repositories like UsTaxes, HMRC, and InlandRevenue, rather than the usual suspicious or low-star GitHub repositories. Jacob Malimban, a researcher at Cofense, noted that this is a shift from the traditional methods, where threat actors create their own malicious GitHub repositories.

The attack abuses GitHub's infrastructure by uploading malicious files as comments in well-known repositories. Once uploaded, the comment is deleted, but the link to the malware file remains active. This method, first discovered by OALABS Research earlier this year, leaves little trace, making it difficult for security teams to detect the threat.

"Emails containing links to GitHub are effective at bypassing email security systems because GitHub is a trusted domain," said Malimban. Attackers use these links to deliver the malware archive directly through email, avoiding other methods like QR codes or Google redirects.

This is not the only new tactic observed in recent phishing attacks. Barracuda Networks has reported other innovative methods used by cybercriminals, such as ASCII- and Unicode-based QR codes and blob URLs. These tactics make it more challenging for security systems to block malicious content.

A blob URL, as explained by security researcher Ashitosh Deshnur, is a type of link used by web browsers to handle binary data like files or images directly in the browser, bypassing the need for external servers. This tactic gives attackers another way to deliver harmful content undetected.

Additionally, cybersecurity firm ESET has uncovered new scams targeting popular accommodation booking platforms like Booking.com and Airbnb. Scammers are using compromised accounts of legitimate hotels to contact customers, asking them to resolve fake payment issues by clicking on malicious links. The rise in such attacks was noted in July 2024, with attackers focusing on customers who had recently booked or made payments.

The group behind these booking scams, known as Telekopye, has also improved its toolkit by automating the creation of phishing pages and using chatbots to communicate with victims. Despite the sophistication of these scams, law enforcement agencies in Czechia and Ukraine arrested several members of the group in late 2023. Authorities revealed that the criminals recruited individuals in difficult life situations, offering them "easy money" for assisting in these schemes.

As these attacks become more creative and harder to detect, businesses in the finance, insurance, and hospitality sectors need to remain vigilant and adopt stronger cybersecurity measures to protect their systems and customers.

In India, there are currently 13.2 million developers using GitHub, compared to approximately 20 million in the US. India also ranks second globally, after the US, in the number of generative artificial intelligence (genAI) projects hosted on GitHub.

Entrepreneur Staff

Entrepreneur Staff

Editor

For more than 30 years, Entrepreneur has set the course for success for millions of entrepreneurs and small business owners. We'll teach you the secrets of the winners and give you exactly what you need to lay the groundwork for success.
Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Leadership

How Successful Leaders Get More Done in Less Time

The most successful leaders don't work longer; they manage their time with intention. Here's how to master time-blocking, prioritization and delegation to get more done in less time.

News and Trends

Kolkata-Based Lab-Grown Diamond Brand Jewelbox Secures USD 3.2 Mn

The startup will primarily use the funds to expand its retail footprint, growing from eight stores to 30 locations by the end of this year.

Science & Technology

How Can Marketers Use ChatGPT? Here Are the Top 11 Uses.

With the recent developments in AI and the popularity of ChatGPT, you may want to integrate AI into your marketing practices. Find out how.

Side Hustle

This Couple Started a Side Hustle to Improve a 'Terribly Made' Bathroom Essential. Now the Business Earns More Than $3 Million a Year.

Michael Fine and Lisa Schulner-Fine launched lifestyle brand Quiet Town in 2016 and have been growing it ever since.

Marketing

5 Ways ChatGPT Will Impact Digital Marketing

ChatGPT is creating ripples across the digital landscape right now. Here are five ways it can benefit your ads, campaigns and marketing strategies.