Malicious Go Module Reveals 222-Repository GitHub Malware Lure Network

· Original article ↗

Summary

Socket Dev Research details a malicious Go module and a 222-repository GitHub lure network across 190 accounts, tracing a hidden PowerShell staging chain to Windows RAT and infostealer activity. The Go security team blocked the module.

Key points

  • The investigation identified 222 confirmed lure repositories across 190 accounts, using automated GitHub Actions commits to appear active and maintained.
  • A fake DNS/subdomain scanner module launches hidden PowerShell, which decodes and executes a staged script; the project may not run reliably through a normal Go build or install path.
  • The loader retrieves encrypted payload-location data from public dead drops, then downloads a password-protected archive and launches its contents from a fake Microsoft Photos directory.
  • Analyzed activity included RAT and infostealer capabilities; the repository cluster also contained at least 14 confirmed malware files, including Vidar-related samples and Monero cryptominers.
  • Reported behaviors include browser-data access, persistence, defense evasion, screenshot collection, and communication through Telegram or other public web services.
  • The researchers reported the module and GitHub infrastructure; the Go security team reviewed the report and blocked the module from its proxy.

Article Details

Attack Vectors
  • A malicious scanner-themed Go module impersonated a legitimate dnsub project and embedded Windows loader logic before the apparent scanner code. The observed project was incomplete and might not execute through normal Go build or install paths without modification.
  • Hidden PowerShell downloaded encoded staging content, decoded it with certutil, and executed the resulting script with execution-policy bypass.
  • A layered PowerShell resolver retrieved encrypted payload-location material from public-service dead drops and fallback locations, then decrypted a GitHub release archive URL.
  • A password-protected archive delivered a Windows application environment that launched a payload from a fake Microsoft Photos directory.
  • Threat actor-controlled repositories used automated synthetic commits, owner-specific commit attribution, and repeated lure themes to appear active and recently maintained.
  • Some repositories distributed malware directly through source-tree files or release assets; one used a right-to-left-override filename to disguise a Windows .scr executable.
Defensive Notes
  • Prioritize behavioral detections and infrastructure clustering rather than relying exclusively on replaceable domains, email addresses, repository names, or payload URLs.
  • Inspect every-minute workflows that force-push synthetic commits, repeatedly rewrite timestamp or log files, and combine owner-name attribution with reused commit metadata.
  • Review package code for hidden shell execution, certificate decoding, disabled certificate validation, and retrieval of encrypted payload-location material from public services.
  • Treat obscure or newly published packages cautiously when they impersonate known utilities, exhibit abnormal version volume, or request scripts and installers outside normal package-manager expectations.
  • Blocking only one dead-drop location or the final archive URL may leave alternative resolver paths available.
  • The researchers reported the infrastructure to the hosting platform and the malicious module to its ecosystem security team. The latter reviewed the report and blocked the module from its module proxy.
  • The confirmed infrastructure count required the threat actor-linked email and synthetic commit-farming workflow to appear together; unrelated search hits and other projects belonging to associated accounts were not automatically classified as malicious.

Indicators of compromise

TypeIndicatorContext
DOMAINmuckcoding[.]comThreat infrastructure serving the encoded PowerShell staging content retrieved by the malicious Go module.
DOMAINmuckdeveloper[.]comThreat infrastructure hosting encrypted payload-location material for the PowerShell dead-drop resolver.
EMAILischhfd83@rambler[.]ruThreat actor-linked commit email reused with synthetic GitHub Actions commit-farming workflows across the confirmed repository network.
SHA256129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bffLayer 1 encrypted PowerShell blob in the malicious loader.
SHA256235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA2562f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7dConfirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA25633497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA25645126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA2564ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4Recovered current\Microsoft.exe launcher executed from the masqueraded application directory.
SHA25651cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807Encrypted payload-location blob recovered from the resolver's dead-drop material.
SHA25657e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629Layer 2 encrypted PowerShell blob in the malicious loader.
SHA25673c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2Recovered password-protected Quixo.7z Windows payload archive.
SHA256810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA25686819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0cLayer 1 decrypted PowerShell script in the malicious loader.
SHA256938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879feDecoded PowerShell stage associated with AsyncRAT and Quasar detections and RAT/infostealer-like behavior.
SHA2569df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7aConfirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4Related GitHub-hosted Quixo.7z sample associated with Remcos-style RAT activity.
SHA256b27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005eConfirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63Final visible decoded PowerShell loader logic.
SHA256e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acadConfirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783fConfirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
SHA256f245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories.
URLhxxps[:]//docs[.]google[.]com/document/d/1PnogKWvfa3ZcCnmKfnb3pJYXMBmcQe5k_6bBuPUailQ/export?format=txtGoogle Docs payload-location dead drop listed in the article's IOC section.
URLhxxps[:]//gitcode[.]com/LastWer/MicrosoftCur/rawSpecific GitCode resource embedded as a fallback source of encrypted payload-location material.
URLhxxps[:]//github[.]com/tb78/expresso/releases/download/Release/Quixo[.]7zPassword-protected payload archive URL listed in the article's IOC section.
URLhxxps[:]//muckcoding[.]com/LG-LW/Api-CertificateEncoded PowerShell staging resource downloaded as api.db and decoded into L.ps1.
URLhxxps[:]//muckdeveloper[.]com/LGTV/MicrosoftCurPrimary dead-drop resource hosting encrypted payload-location material.
URLhxxps[:]//pastebin[.]com/raw/xy32SJgfSpecific public-service dead drop used to retrieve encrypted payload-location material.
URLhxxps[:]//rlim[.]com/MicrosoftCur/rawSpecific dead-drop resource used to retrieve encrypted payload-location material.
URLhxxps[:]//t[.]me/s/dwmicSpecific Telegram dead-drop location used by the malicious payload-location resolver.
URLhxxps[:]//www[.]instagram[.]com/p/DG20Zt9Mj4P/Fallback dead-drop post listed in the article's IOC section.
URLhxxps[:]//youtu[.]be/GAS67zAOsscSpecific public-platform fallback resource embedded in the malicious payload-location resolver.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationMalicious Go code was visually obscured with excessive horizontal whitespace, and later staging relied on multiple obfuscated script layers.T1027.013 · Encrypted/Encoded FileThe loader used Base64-encoded and XOR-encrypted PowerShell blobs, encrypted resolver material, and a password-protected payload archive.T1036.005 · Match Legitimate Resource Name or LocationThe payload ran as Microsoft.exe under C:\ProgramData\Windows.Microsoft.Photos\current\, a fake Microsoft Photos installation path.T1053.005 · Scheduled TaskThe analyzed payload chain used scheduled task activity for persistence.T1055 · Process InjectionLower-level payload analysis observed WriteProcessMemory and SetThreadContext usage supporting process-injection activity.T1059.001 · PowerShellThe Go loader launched PowerShell, and successive PowerShell stages used Invoke-Expression to execute decrypted scripts.T1071.001 · Web ProtocolsThe chain retrieved staging resources over HTTPS, and downstream analysis reported communication with Telegram or other public web-service infrastructure.T1102.001 · Dead Drop ResolverThe resolver queried specific public-service resources for encrypted payload-location material marked with LastW and used fallback sources if others failed.T1105 · Ingress Tool TransferThe staging chain downloaded encoded PowerShell content and the Quixo.7z payload archive onto the Windows host.T1113 · Screen CapturePayload analysis reported preparation for screenshot collection, and the article identified CaptureScreens.ps1 as a screenshot-collection script.T1140 · Deobfuscate/Decode Files or Informationcertutil decoded api.db into L.ps1; subsequent scripts decoded Base64 data, performed XOR decryption, decrypted payload-location material, and extracted the protected archive.T1195.001 · Compromise Software Dependencies and Development ToolsA published scanner-themed Go module embedded Windows malware-staging logic; the ecosystem security team subsequently blocked it from the module proxy.T1204.002 · Malicious FileDeceptive software repositories sought to induce users to download, build, or run malicious files and setup instructions.T1543.003 · Windows ServiceThe analyzed Windows payload chain used service activity for persistence.T1555.003 · Credentials from Web BrowsersThe article associated browser-profile data access in the payload chain with infostealer-like and credential-access behavior.T1564.003 · Hidden WindowThe loader hid PowerShell windows and launched the staged Microsoft.exe payload with a hidden window.T1608.001 · Upload MalwareThreat actor-controlled GitHub repositories hosted confirmed malware in source trees and release assets, including the payload archive and an Interwebs.exe release asset.T1685 · Disable or Modify ToolsDynamic analysis reported that the payload chain modified Microsoft Defender settings as part of defense-evasion activity.

People

Malware

Vendors

Products

Tools

Related Articles