Fake zero-day PoC exploits on GitHub push Windows, Linux malware
Someone created a bunch of github profiles impersonating real researchers alongside fake Twitter accounts. Pretty fascinating, really.
https://www.bleepingcomputer.com/news/security/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware/Open linkView original on infosec.pub
3 replies
huh, this is weird. one would think people would use separate machines / vms to test zero day exploits, not their main machines.
They're not even that stealthy. The code is bullshit,
gitignorefolder is super suspicious and malware is just a binary within the zip file. Clearly meant for script kiddies.Any attribution?