Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New Campaigns Distribute Malware via Open Source Hacking Tools

Posted on June 19, 2025June 19, 2025 By CWS

Safety researchers at Pattern Micro and ReversingLabs have uncovered two recent campaigns focusing on crimson groups, novice cybercriminals, and developer environments through trojanized open supply hacking instruments.

Attributed by Pattern Micro to a risk actor named Water Curse, one of many campaigns concerned at the least 76 GitHub accounts linked to repositories that had malicious payloads injected into construct scripts and challenge recordsdata.

The payloads have been designed to steal credentials, browser knowledge, and session tokens, in addition to to offer the risk actor with persistent distant entry to the compromised programs.

In response to Pattern Micro, Water Curse is a financially motivated adversary that seemingly started utilizing GitHub accounts for nefarious actions in March 2023.

“Water Curse primarily targets crimson groups and penetration testers, builders, and avid gamers, reflecting a hybrid technique that blends provide chain compromise with opportunistic exploitation throughout digital communities,” the cybersecurity agency notes.

The risk actor hid the malicious payloads within the Visible Studio challenge configuration recordsdata of an SMTP e mail bomber and Sakura RAT. Instruments employed all through the marketing campaign embrace C#, JavaScript, PowerShell, and VBS scripts, and compiled PE binaries.

ReversingLabs has uncovered a marketing campaign involving greater than 67 GitHub repositories promising Python-based hacking instruments, however delivering trojanized look-alikes of different repositories.

As a part of the marketing campaign, attributed to a risk actor named Banana Squad, every GitHub account had just one repository listed underneath its identify, suggesting that malware distribution was the only goal of each one in every of them.Commercial. Scroll to proceed studying.

The marketing campaign started in early June, however ReversingLabs linked it to earlier stories on comparable malicious exercise flagged by Checkmarx in 2023.

Each incidents mirror a marketing campaign lately uncovered by Sophos, which seems linked to a distribution-as-a-service (DaaS) operation that has been ongoing since 2022, and which has used 1000’s of GitHub accounts to distribute malware embedded in open supply instruments.

Associated: Malicious NPM Packages Disguised as Categorical Utilities Permit Attackers to Wipe Techniques

Associated: Cyber Insights 2025: Open Supply and Software program Provide Chain Safety

Associated: Open Supply Bundle Entry Factors Could Result in Provide Chain Assaults

Security Week News Tags:Campaigns, Distribute, Hacking, Malware, Open, Source, Tools

Post navigation

Previous Post: BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
Next Post: Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War

Related Posts

Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Security Week News
ZeroRISC Raises $10 Million for Open Source Silicon Security Solutions Security Week News
Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Security Week News
Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War Security Week News
Cybersecurity M&A Roundup: 42 Deals Announced in May 2025 Security Week News
Critical Vulnerability Patched in SAP NetWeaver Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War
  • New Campaigns Distribute Malware via Open Source Hacking Tools
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Chain IQ, UBS Data Stolen in Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2025
  • May 2025

Recent Posts

  • Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War
  • New Campaigns Distribute Malware via Open Source Hacking Tools
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Chain IQ, UBS Data Stolen in Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News