Malicious Go Module Reveals 222-Repository GitHub Malware Lure Network

Summary
Socket Dev Research details a malicious Go module and a 222-repository GitHub lure network across 190 accounts, tracing a hidden PowerShell staging chain to Windows RAT and infostealer activity. The Go security team blocked the module.
Key points
- The investigation identified 222 confirmed lure repositories across 190 accounts, using automated GitHub Actions commits to appear active and maintained.
- A fake DNS/subdomain scanner module launches hidden PowerShell, which decodes and executes a staged script; the project may not run reliably through a normal Go build or install path.
- The loader retrieves encrypted payload-location data from public dead drops, then downloads a password-protected archive and launches its contents from a fake Microsoft Photos directory.
- Analyzed activity included RAT and infostealer capabilities; the repository cluster also contained at least 14 confirmed malware files, including Vidar-related samples and Monero cryptominers.
- Reported behaviors include browser-data access, persistence, defense evasion, screenshot collection, and communication through Telegram or other public web services.
- The researchers reported the module and GitHub infrastructure; the Go security team reviewed the report and blocked the module from its proxy.
Article Details
- Attack Vectors
- A malicious scanner-themed Go module impersonated a legitimate dnsub project and embedded Windows loader logic before the apparent scanner code. The observed project was incomplete and might not execute through normal Go build or install paths without modification.
- Hidden PowerShell downloaded encoded staging content, decoded it with certutil, and executed the resulting script with execution-policy bypass.
- A layered PowerShell resolver retrieved encrypted payload-location material from public-service dead drops and fallback locations, then decrypted a GitHub release archive URL.
- A password-protected archive delivered a Windows application environment that launched a payload from a fake Microsoft Photos directory.
- Threat actor-controlled repositories used automated synthetic commits, owner-specific commit attribution, and repeated lure themes to appear active and recently maintained.
- Some repositories distributed malware directly through source-tree files or release assets; one used a right-to-left-override filename to disguise a Windows .scr executable.
- Defensive Notes
- Prioritize behavioral detections and infrastructure clustering rather than relying exclusively on replaceable domains, email addresses, repository names, or payload URLs.
- Inspect every-minute workflows that force-push synthetic commits, repeatedly rewrite timestamp or log files, and combine owner-name attribution with reused commit metadata.
- Review package code for hidden shell execution, certificate decoding, disabled certificate validation, and retrieval of encrypted payload-location material from public services.
- Treat obscure or newly published packages cautiously when they impersonate known utilities, exhibit abnormal version volume, or request scripts and installers outside normal package-manager expectations.
- Blocking only one dead-drop location or the final archive URL may leave alternative resolver paths available.
- The researchers reported the infrastructure to the hosting platform and the malicious module to its ecosystem security team. The latter reviewed the report and blocked the module from its module proxy.
- The confirmed infrastructure count required the threat actor-linked email and synthetic commit-farming workflow to appear together; unrelated search hits and other projects belonging to associated accounts were not automatically classified as malicious.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | muckcoding[.]com | Threat infrastructure serving the encoded PowerShell staging content retrieved by the malicious Go module. |
| DOMAIN | muckdeveloper[.]com | Threat infrastructure hosting encrypted payload-location material for the PowerShell dead-drop resolver. |
ischhfd83@rambler[.]ru | Threat actor-linked commit email reused with synthetic GitHub Actions commit-farming workflows across the confirmed repository network. | |
| SHA256 | 129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff | Layer 1 encrypted PowerShell blob in the malicious loader. |
| SHA256 | 235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 2f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7d | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 33497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4 | Recovered current\Microsoft.exe launcher executed from the masqueraded application directory. |
| SHA256 | 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 | Encrypted payload-location blob recovered from the resolver's dead-drop material. |
| SHA256 | 57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629 | Layer 2 encrypted PowerShell blob in the malicious loader. |
| SHA256 | 73c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2 | Recovered password-protected Quixo.7z Windows payload archive. |
| SHA256 | 810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c | Layer 1 decrypted PowerShell script in the malicious loader. |
| SHA256 | 938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | 969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fe | Decoded PowerShell stage associated with AsyncRAT and Quasar detections and RAT/infostealer-like behavior. |
| SHA256 | 9df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7a | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4 | Related GitHub-hosted Quixo.7z sample associated with Remcos-style RAT activity. |
| SHA256 | b27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005e | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63 | Final visible decoded PowerShell loader logic. |
| SHA256 | e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acad | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783f | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| SHA256 | f245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4 | Confirmed malware sample identified in analyzed threat actor-controlled GitHub repositories. |
| URL | hxxps[:]//docs[.]google[.]com/document/d/1PnogKWvfa3ZcCnmKfnb3pJYXMBmcQe5k_6bBuPUailQ/export?format=txt | Google Docs payload-location dead drop listed in the article's IOC section. |
| URL | hxxps[:]//gitcode[.]com/LastWer/MicrosoftCur/raw | Specific GitCode resource embedded as a fallback source of encrypted payload-location material. |
| URL | hxxps[:]//github[.]com/tb78/expresso/releases/download/Release/Quixo[.]7z | Password-protected payload archive URL listed in the article's IOC section. |
| URL | hxxps[:]//muckcoding[.]com/LG-LW/Api-Certificate | Encoded PowerShell staging resource downloaded as api.db and decoded into L.ps1. |
| URL | hxxps[:]//muckdeveloper[.]com/LGTV/MicrosoftCur | Primary dead-drop resource hosting encrypted payload-location material. |
| URL | hxxps[:]//pastebin[.]com/raw/xy32SJgf | Specific public-service dead drop used to retrieve encrypted payload-location material. |
| URL | hxxps[:]//rlim[.]com/MicrosoftCur/raw | Specific dead-drop resource used to retrieve encrypted payload-location material. |
| URL | hxxps[:]//t[.]me/s/dwmic | Specific Telegram dead-drop location used by the malicious payload-location resolver. |
| URL | hxxps[:]//www[.]instagram[.]com/p/DG20Zt9Mj4P/ | Fallback dead-drop post listed in the article's IOC section. |
| URL | hxxps[:]//youtu[.]be/GAS67zAOssc | Specific public-platform fallback resource embedded in the malicious payload-location resolver. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationMalicious Go code was visually obscured with excessive horizontal whitespace, and later staging relied on multiple obfuscated script layers.T1027.013 · Encrypted/Encoded FileThe loader used Base64-encoded and XOR-encrypted PowerShell blobs, encrypted resolver material, and a password-protected payload archive.T1036.005 · Match Legitimate Resource Name or LocationThe payload ran as Microsoft.exe under C:\ProgramData\Windows.Microsoft.Photos\current\, a fake Microsoft Photos installation path.T1053.005 · Scheduled TaskThe analyzed payload chain used scheduled task activity for persistence.T1055 · Process InjectionLower-level payload analysis observed WriteProcessMemory and SetThreadContext usage supporting process-injection activity.T1059.001 · PowerShellThe Go loader launched PowerShell, and successive PowerShell stages used Invoke-Expression to execute decrypted scripts.T1071.001 · Web ProtocolsThe chain retrieved staging resources over HTTPS, and downstream analysis reported communication with Telegram or other public web-service infrastructure.T1102.001 · Dead Drop ResolverThe resolver queried specific public-service resources for encrypted payload-location material marked with LastW and used fallback sources if others failed.T1105 · Ingress Tool TransferThe staging chain downloaded encoded PowerShell content and the Quixo.7z payload archive onto the Windows host.T1113 · Screen CapturePayload analysis reported preparation for screenshot collection, and the article identified CaptureScreens.ps1 as a screenshot-collection script.T1140 · Deobfuscate/Decode Files or Informationcertutil decoded api.db into L.ps1; subsequent scripts decoded Base64 data, performed XOR decryption, decrypted payload-location material, and extracted the protected archive.T1195.001 · Compromise Software Dependencies and Development ToolsA published scanner-themed Go module embedded Windows malware-staging logic; the ecosystem security team subsequently blocked it from the module proxy.T1204.002 · Malicious FileDeceptive software repositories sought to induce users to download, build, or run malicious files and setup instructions.T1543.003 · Windows ServiceThe analyzed Windows payload chain used service activity for persistence.T1555.003 · Credentials from Web BrowsersThe article associated browser-profile data access in the payload chain with infostealer-like and credential-access behavior.T1564.003 · Hidden WindowThe loader hid PowerShell windows and launched the staged Microsoft.exe payload with a hidden window.T1608.001 · Upload MalwareThreat actor-controlled GitHub repositories hosted confirmed malware in source trees and release assets, including the payload archive and an Interwebs.exe release asset.T1685 · Disable or Modify ToolsDynamic analysis reported that the payload chain modified Microsoft Defender settings as part of defense-evasion activity.
People
Andrew O’DonnellSophos researcher who previously reported ischhfd83-linked repository-backdoor activity with tradecraft overlapping the investigated cluster.Matt WixeySophos researcher who previously reported ischhfd83-linked repository-backdoor activity with tradecraft overlapping the investigated cluster.
Malware
AsyncRATAsyncRAT, Quasar, Remcos, and Infostealer Activity#BitMinerspyware/dropper payloads, trojan-downloader activity, and Monero cryptominers related to XMRig/BitMiner.QuasarAsyncRAT, Quasar, Remcos, and Infostealer Activity#Remcos RATAsyncRAT, Quasar, Remcos, and Infostealer Activity#Vidaractor-controlled repositories, we confirmed at least 14 malware files, including loaders and downloaders, Vidar infostealer, spyware/dropper payloads, trojan-downloader activity, and Monero cryptominers related toXMRiginfostealer, spyware/dropper payloads, trojan-downloader activity, and Monero cryptominers related to XMRig/BitMiner.
Vendors
Products
7-Ziparchive into a temporary staging directory: C:\Users\Public\Documents\umun\. The loader also prepares a 7-Zip command-line extractor under: C:\ProgramData\zipathh\7zrr.exe. The archive password is hardcoded:GitHubOur investigation began with a malicious Go module, github[.]com/kaleidora/dnsub-scanning-tool, that posed as a DNS/subdomain scanner. The module did more than impersonate a developer utility: it exposed a WindowsGitHub Actionsa conservative high-confidence core: repositories where the threat actor-linked email and synthetic GitHub Actions commit-farming workflow appeared together.GoOur investigation began with a malicious Go module, github[.]com/kaleidora/dnsub-scanning-tool, that posed as a DNS/subdomain scanner. The module did more than impersonate a developer utility: it exposed a WindowsMicrosoft Defenderevasion, persistence, collection, and RAT-style command and control. The payload chain modifies Microsoft Defender and UAC settings, uses scheduled task and service activity for persistence, stages additionalMicrosoft Windowsposed as a DNS/subdomain scanner. The module did more than impersonate a developer utility: it exposed a Windows malware-staging chain that used hidden PowerShell execution, public dead-drop resolution, protectedPowerShellmore than impersonate a developer utility: it exposed a Windows malware-staging chain that used hidden PowerShell execution, public dead-drop resolution, protected archive delivery, and RAT/infostealer deployment.