Jump to content

Stargazer Goblin

From Wikipedia, the free encyclopedia

Stargazer Goblin is a threat actor (since August 2022) which operate a network (over 3.000 inauthentic GitHub accounts) known as Stargazers Ghost Network that distribute malware (ransomware, infostealers) such as: Atlantida Stealer, Rhadamanthys, and share malicious links.[1][2][3][4][5] It acts as a Distribution as a Service (DaaS).[6][7][8][9]

References

[edit]
  1. ^ https://thehackernews.com/2024/07/stargazer-goblin-creates-3000-fake.html%7C
  2. ^ Burgess, Matt. "A Hacker 'Ghost' Network Is Quietly Spreading Malware on GitHub" – via www.wired.com.
  3. ^ Ezenwa, Eric. "How 'Stargazer Goblin' leveraged GitHub for large-scale malware attacks". Interesting Engineering.
  4. ^ Horwood, Penny. "Malicious 'ghost' DaaS network spreading malware through GitHub". www.computing.co.uk.
  5. ^ "Stargazers Ghost: $100K GitHub Malware Network Exposed". July 29, 2024.
  6. ^ "Threat Actor Stargazer Goblin Uses Over 3,000 GitHub Accounts for Malware Distribution - CPO Magazine".
  7. ^ ""'Stargazer Goblin' Amasses Rogue GitHub Accounts to Spread Malware" | Science of Security Virtual Organization". sosvo-staging.isis.vanderbilt.edu.
  8. ^ "Network of 3,000 GitHub Accounts Used for Malware Distribution - SecurityWeek".
  9. ^ "3,000 "ghost accounts" on GitHub spreading malware".