Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters

Score: 71/100 3 articles 100.0% Similarity 17 hours ago

Activity Timeline

Microsoft Teams Call Weaponized to Deploy and Exec...
Cybersecurity News
Jul 16
18:39
MaaS operation using Emmenhtal and Amadey linked t...
Cisco Talos Intelligence
Jul 17
10:00
Hackers Use GitHub Repositories to Host Amadey Mal...
The Hacker News
Primary Article
Jul 17
17:40
Threat actors are leveragingpublic GitHub repositoriesto host malicious payloads and distribute them via Amadey as part of a campaign observed in April 2025. "The MaaS [malware-as-a-service] operators used fake GitHub accounts to host payloads, tools, and Amadey plug-ins, likely as an attempt to bypass web filtering and for ease of use," Cisco Talos researchers Chris Neal and Craig Jacksonsaidin a report published today. The cybersecurity company said the attack chains leverage a malware loader calledEmmenhtal(aka PEAKLIGHT) to deliver Amadey, which, for its part, downloads various custom payloads from public GitHub repositories operated by the threat actors. The activity shares tactical similarities with an email phishing campaign that used invoice payment and billing-related lures todistributeSmokeLoader via Emmenhtal in February 2025 in attacks targeting Ukrainian entities. Both Emmenhtal and Amadey function as a downloader for secondary payloads like information stealers, although ...

Cluster AI

Beta Organization

Save to Folder

Choose a folder to save this cluster: