Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Campaigns Distribute Malware via Open Source Hacking Tools

New Campaigns Distribute Malware via Open Source Hacking Tools

Posted on June 19, 2025June 19, 2025 By CWS

Safety researchers at Pattern Micro and ReversingLabs have uncovered two recent campaigns focusing on crimson groups, novice cybercriminals, and developer environments through trojanized open supply hacking instruments.

Attributed by Pattern Micro to a risk actor named Water Curse, one of many campaigns concerned at the least 76 GitHub accounts linked to repositories that had malicious payloads injected into construct scripts and challenge recordsdata.

The payloads have been designed to steal credentials, browser knowledge, and session tokens, in addition to to offer the risk actor with persistent distant entry to the compromised programs.

In response to Pattern Micro, Water Curse is a financially motivated adversary that seemingly started utilizing GitHub accounts for nefarious actions in March 2023.

“Water Curse primarily targets crimson groups and penetration testers, builders, and avid gamers, reflecting a hybrid technique that blends provide chain compromise with opportunistic exploitation throughout digital communities,” the cybersecurity agency notes.

The risk actor hid the malicious payloads within the Visible Studio challenge configuration recordsdata of an SMTP e mail bomber and Sakura RAT. Instruments employed all through the marketing campaign embrace C#, JavaScript, PowerShell, and VBS scripts, and compiled PE binaries.

ReversingLabs has uncovered a marketing campaign involving greater than 67 GitHub repositories promising Python-based hacking instruments, however delivering trojanized look-alikes of different repositories.

As a part of the marketing campaign, attributed to a risk actor named Banana Squad, every GitHub account had just one repository listed underneath its identify, suggesting that malware distribution was the only goal of each one in every of them.Commercial. Scroll to proceed studying.

The marketing campaign started in early June, however ReversingLabs linked it to earlier stories on comparable malicious exercise flagged by Checkmarx in 2023.

Each incidents mirror a marketing campaign lately uncovered by Sophos, which seems linked to a distribution-as-a-service (DaaS) operation that has been ongoing since 2022, and which has used 1000’s of GitHub accounts to distribute malware embedded in open supply instruments.

Associated: Malicious NPM Packages Disguised as Categorical Utilities Permit Attackers to Wipe Techniques

Associated: Cyber Insights 2025: Open Supply and Software program Provide Chain Safety

Associated: Open Supply Bundle Entry Factors Could Result in Provide Chain Assaults

Security Week News Tags:Campaigns, Distribute, Hacking, Malware, Open, Source, Tools

Post navigation

Previous Post: BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
Next Post: Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War

Related Posts

Vulnerabilities Exposed Phone Number of Any Google User Vulnerabilities Exposed Phone Number of Any Google User Security Week News
FireCompass Raises  Million for Offensive Security Platform FireCompass Raises $20 Million for Offensive Security Platform Security Week News
BIND Updates Address Critical Security Vulnerabilities BIND Updates Address Critical Security Vulnerabilities Security Week News
Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Security Week News
Fresh MongoDB Vulnerability Exploited in Attacks Fresh MongoDB Vulnerability Exploited in Attacks Security Week News
Data Breach Affects 130,000 at Hightower Holding Data Breach Affects 130,000 at Hightower Holding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark