• 34ºc, Sunny

Cyber security firm Kaspersky: Hackers are creating hundreds of fake GitHub projects to trick users into downloading malicious software that encrypts and steals credentials

Cyber security firm Kaspersky says hackers are creating hundreds of fake GitHub projects to trick users into downloading malicious software that encrypts and steals credentials. Kaspersky analyst Georgy Kucherin said in a report dated February 24 that hackers created hundreds of software feeds on GitHub to host fake projects containing remote access Trojans (RATs), information-stealing programs, and clipboard hijackers. Some of the forgeries include a Telegram bot that manages bitcoin wallets and a tool that automates interactions with Instagram accounts. Mr. Kuchelin added that malicious software creators "go to great lengths" to make the items appear legitimate, including "elaborate" information and instruction files that "may have been generated with artificial intelligence tools". The people behind the malicious project also artificially inflated the number of "commits" (that is, changes to the project), while adding multiple references to specific changes, giving the impression that the project was actively improving.