Just Another Blue Teamer<p>Happy Friday everyone!</p><p>I feel like this has become a weekly PSA but Kaspersky Securelist researchers have identified hundreds of <a href="https://ioc.exchange/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> projects that are serving up malicious code designed to steal saved credentials, cryptocurrency wallets, and browsing history. Sometimes this execution of code leads to the <a href="https://ioc.exchange/tags/ASyncRAT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ASyncRAT</span></a> or <a href="https://ioc.exchange/tags/Quasar" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Quasar</span></a> Backdoor, but the threat remains the same: blindly executing code from GitHub. I hope you enjoy and Happy Hunting!</p><p>The GitVenom campaign: cryptocurrency theft using GitHub</p><p><a href="https://securelist.com/gitvenom-campaign/115694/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">securelist.com/gitvenom-campai</span><span class="invisible">gn/115694/</span></a></p><p>Intel 471 Cyborg Security, Now Part of Intel 471 <a href="https://ioc.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatIntel</span></a> <a href="https://ioc.exchange/tags/ThreatHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatHunting</span></a> <a href="https://ioc.exchange/tags/ThreatDetection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatDetection</span></a> <a href="https://ioc.exchange/tags/HappyHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HappyHunting</span></a> <a href="https://ioc.exchange/tags/readoftheday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>readoftheday</span></a></p>