Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Campaigns Distribute Malware via Open Source Hacking Tools

New Campaigns Distribute Malware via Open Source Hacking Tools

Posted on June 19, 2025June 19, 2025 By CWS

Safety researchers at Pattern Micro and ReversingLabs have uncovered two recent campaigns focusing on crimson groups, novice cybercriminals, and developer environments through trojanized open supply hacking instruments.

Attributed by Pattern Micro to a risk actor named Water Curse, one of many campaigns concerned at the least 76 GitHub accounts linked to repositories that had malicious payloads injected into construct scripts and challenge recordsdata.

The payloads have been designed to steal credentials, browser knowledge, and session tokens, in addition to to offer the risk actor with persistent distant entry to the compromised programs.

In response to Pattern Micro, Water Curse is a financially motivated adversary that seemingly started utilizing GitHub accounts for nefarious actions in March 2023.

“Water Curse primarily targets crimson groups and penetration testers, builders, and avid gamers, reflecting a hybrid technique that blends provide chain compromise with opportunistic exploitation throughout digital communities,” the cybersecurity agency notes.

The risk actor hid the malicious payloads within the Visible Studio challenge configuration recordsdata of an SMTP e mail bomber and Sakura RAT. Instruments employed all through the marketing campaign embrace C#, JavaScript, PowerShell, and VBS scripts, and compiled PE binaries.

ReversingLabs has uncovered a marketing campaign involving greater than 67 GitHub repositories promising Python-based hacking instruments, however delivering trojanized look-alikes of different repositories.

As a part of the marketing campaign, attributed to a risk actor named Banana Squad, every GitHub account had just one repository listed underneath its identify, suggesting that malware distribution was the only goal of each one in every of them.Commercial. Scroll to proceed studying.

The marketing campaign started in early June, however ReversingLabs linked it to earlier stories on comparable malicious exercise flagged by Checkmarx in 2023.

Each incidents mirror a marketing campaign lately uncovered by Sophos, which seems linked to a distribution-as-a-service (DaaS) operation that has been ongoing since 2022, and which has used 1000’s of GitHub accounts to distribute malware embedded in open supply instruments.

Associated: Malicious NPM Packages Disguised as Categorical Utilities Permit Attackers to Wipe Techniques

Associated: Cyber Insights 2025: Open Supply and Software program Provide Chain Safety

Associated: Open Supply Bundle Entry Factors Could Result in Provide Chain Assaults

Security Week News Tags:Campaigns, Distribute, Hacking, Malware, Open, Source, Tools

Post navigation

Previous Post: BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
Next Post: Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War

Related Posts

Reach Security Raises  Million for Exposure Management Solution Reach Security Raises $10 Million for Exposure Management Solution Security Week News
Ransomware Group Claims Attack on Belk Ransomware Group Claims Attack on Belk Security Week News
Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Security Week News
Developer Who Hacked Former Employer’s Systems Sentenced to Prison Developer Who Hacked Former Employer’s Systems Sentenced to Prison Security Week News
Intel Employee Data Exposed by Vulnerabilities Intel Employee Data Exposed by Vulnerabilities Security Week News
Critical Dolby Vulnerability Patched in Android Critical Dolby Vulnerability Patched in Android Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News