Auteur Sujet: [Trend]Winnti Abuses GitHub for C&C Communications  (Lu 2659 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[Trend]Winnti Abuses GitHub for C&C Communications
« le: mars 23, 2017, 21:00:41 »
Winnti Abuses GitHub for C&C Communications

Developers constantly need to modify and rework their source codes when releasing new versions of applications or coding projects they create and maintain. This is what makes GitHub—an online repository hosting service that provides version control management—popular. In many ways, it’s like a social networking site for programmers and developers, one that provides a valuable platform for code management, sharing, collaboration, and integration.


GitHub is no stranger to misuse, however. Open-source ransomware projects EDA2 and Hidden Tear—supposedly created for educational purposes—were hosted on GitHub, and have since spawned various offshoots that have been found targeting enterprises. Tools that exploited vulnerabilities in Internet of Things (IoT) devices were also made available on GitHub. Even the Limitless Keylogger, which was used in targeted attacks, was linked to a GitHub project.


Other threat actors have abused GitHub—namely, the Winnti APT group. This time, however, Winnti abused GitHub by turning it into a conduit for the command and control (C&C) communications of their seemingly newfangled backdoor (detected by Trend Micro as BKDR64_WINNTI.ONM).


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


Winnti Abuses GitHub for C&C Communications


Source: Winnti Abuses GitHub for C&C Communications

Tags: