An attacker, disguised as a job seeker, distributing malware on GitHub

2025-06-03 ENKI

https://www.enki.co.kr/en/media-center/tech-blog/an-attacker-disguised-as-a-job-seeker-distributing-malware-on-github

Thumbnail for An attacker, disguised as a job seeker, distributing malware on GitHub

ENKI analyzed GitHub repositories where an actor posing as a full-stack and blockchain developer hid malicious scripts inside apparently legitimate projects. In the Ly_AutoPayBot repository, malicious code was concealed far below the visible logger.ts content and executed whenever the module was imported, downloading a disguised DLL from Catbox and launching it through rundll32. The DLL backdoor created multiple threads, used IOCP-based HTTP POST communication with its C&C server, generated an infected-host identifier from the volume GUID path, and protected C&C data and internal strings with Base64 and MT19937-based routines. The excerpt explicitly notes that North Korean IT workers have used fake LinkedIn and GitHub developer profiles for revenue and information theft, but it does not claim the analyzed GitHub actor is North Korean or Lazarus-linked.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8b6d6807213c21c84192cc697d96396… 2025-06-03 2025-06-03
HASH 5527f0acb4755e4402434f84c0aac60… 2025-06-03 2025-06-03
HASH 13412b54e3e8f30d3179e54cc653dc6… 2025-06-03 2025-06-03
HASH 52046ad374041f0cabc47e897e10de8… 2025-06-03 2025-06-03
HASH 7790c55c5dded39c0a6a0eabf05665c… 2025-06-03 2025-06-03
HASH 6ac3bd5e67f5ba1f8effbb53d25078e… 2025-06-03 2025-06-03
URL https://files.catbox.moe/mur3el… 2025-06-03 2025-06-03
URL https://app.mercuryswap.io 2025-06-03 2025-06-03
URL https://files.catbox.moe/zxmneq… 2025-06-03 2025-06-03
URL https://www.dropbox.com/scl/fi/… 2025-06-03 2025-06-03
DOMAIN app.mercuryswap.io 2025-06-03 2025-06-03
IPv4 166.88.117.246 2025-06-03 2025-06-03
IPv4 166.88.90.143 2025-06-03 2025-06-03

Related Reports

« Back