Featured Post

Twenty Practical Steps to Better Corporate Governance | The Corporate Secretaries International Association (CSIA)

Twenty Practical Steps to Better Corporate Governance | The Corporate Secretaries International Association (CSIA) Please click the li...

Thursday, March 30, 2017

Someone is putting lots of work into hacking Github developers

http://ift.tt/2nxbrk0
espionage-800x614.jpg

Enlarge (credit: MGM)

Open-source developers who use Github are in the cross-hairs of advanced malware that has steal passwords, download sensitive files, take screenshots, and self-destruct when necessary.

Dimnie, as the reconnaissance and espionage trojan is known, has largely flown under the radar for the past three years. It mostly targeted Russians until early this year, when a new campaign took aim at multiple owners of Github repositories. One commenter in this thread reported the initial infection e-mail was sent to an address that was used solely for Github, and researchers with Palo Alto Networks, the firm that reported the campaign on Tuesday, told Ars they have no evidence it targeted anyone other than Github developers.

"Both messages appearing to be hand-crafted, and the reference to today's data in the attachment file name IMHO hint at a focused campaign explicitly targeting targets perceived as 'high return investments,' such as developers (possibly working on popular/open-source projects,)" someone who received two separate infection e-mails reported in the thread.

Read 4 remaining paragraphs | Comments

index?i=RHMmM9aCKOk:k0C0YIe4n7Q:V_sGLiPB index?i=RHMmM9aCKOk:k0C0YIe4n7Q:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA


March 30, 2017 at 05:29AM

http://ift.tt/2o9GmFY

from Dan Goodin

http://ift.tt/2o9GmFY

No comments:

Post a Comment