• ABOUT
  • PRIVACY
  • CONTACT
  • ADVERTISE
No Result
View All Result
KeralaNews 24x7
Monday, June 30, 2025
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL
No Result
View All Result
News 24x7
No Result
View All Result

Microsoft Takes Down Malicious GitHub Repositories in Massive Malvertising Crackdown

Satish Ray by Satish Ray
4 months ago
Reading Time: 3 mins read
0
0
0
SHARES
1
VIEWS
FBXLinkedinWhatsAppTelegram

Microsoft has dismantled a network of GitHub repositories fueling a widespread malvertising campaign that compromised nearly one million devices globally. The tech giant’s security teams detected the operation in December 2024, tracing infections back to malware-laden ads injected into pirated streaming sites.

Malicious Ads on Pirated Streaming Platforms Led to Infections

Security researchers found that cybercriminals embedded hidden redirections into video frames on illegal streaming platforms. These malicious scripts rerouted unsuspecting viewers through multiple redirectors before ultimately landing them on GitHub repositories hosting malware.

  • The initial lure was video ads on pirated content websites.
  • Users clicking or even just viewing these videos were silently redirected.
  • Traffic passed through multiple layers of malicious redirectors before reaching a GitHub-hosted payload.

Once on the infected repositories, victims unknowingly downloaded malware capable of gathering system details and deploying additional threats.

GitHub cybersecurity threats

Multi-Stage Attack: How the Malware Spread

The attack didn’t stop at a single infection. Microsoft’s investigation uncovered a sophisticated, multi-stage process designed to persist within systems and exfiltrate sensitive data.

  1. Stage One: Malicious GitHub repositories delivered the first malware payload, which collected system information such as memory size, screen resolution, OS version, and user paths.
  2. Stage Two: The collected data was transmitted to an external server, while a second set of malicious scripts prepared for deeper infiltration.
  3. Stage Three: A PowerShell script downloaded the NetSupport RAT (remote access trojan), granting attackers persistent control over compromised systems.
  4. Final Stage: The malware deployed additional tools, including Lumma and Doenerium information stealers, to extract browser credentials and other sensitive data.

In some cases, the infection chain varied. If an executable file was used instead of a PowerShell script, it triggered an AutoIt-based execution method. This involved dropping a disguised AutoIt interpreter (.com or .scr file) alongside JavaScript components to gain persistence and execute further commands.

Microsoft’s Response and the Scale of the Attack

Microsoft responded swiftly to take down the malicious GitHub repositories, limiting further infections. However, the company’s security teams found that GitHub was not the only hosting service exploited in the campaign. Attackers also used Dropbox and Discord to distribute payloads, demonstrating how cybercriminals leverage multiple platforms to evade detection.

The campaign’s reach was vast, affecting both individual consumers and enterprise networks across industries. Microsoft tracked the activity under the name Storm-0408, a designation for threat actors specializing in remote access and information-stealing malware.

What’s Next? The Ongoing Battle Against Malvertising

Malvertising remains a major cybersecurity threat, particularly as attackers refine their methods to bypass traditional security defenses. Microsoft’s report sheds light on the growing sophistication of these campaigns, making it clear that:

  • Ad networks remain a weak point—Malicious actors continue to exploit legitimate advertising platforms to distribute malware.
  • Cloud services are being weaponized—Platforms like GitHub, Dropbox, and Discord are increasingly used to host malware, requiring stricter content moderation.
  • Multi-stage attacks are becoming the norm—Simple malware infections are evolving into layered, persistent attacks that are harder to detect and mitigate.

While Microsoft’s intervention has disrupted this particular campaign, the fight against malvertising is far from over. As attackers adapt, cybersecurity teams must stay ahead with proactive threat detection and mitigation strategies.

ShareTweetShareSendShare
Satish Ray

Satish Ray

Satish Ray is a senior content writer with a penchant for weaving words into captivating narratives. With years of experience in crafting compelling stories across diverse industries, he excels in delivering engaging content that resonates with readers and drives results.

Related Posts

Lhuan-dre Pretorius batting 2025 Zimbabwe Test

Teen Prodigies Shine Bright as Lhuan-dre Pretorius and Smriti Mandhana Etch Their Names in Cricket History

4 hours ago
indian stock exchange trading floor

Nifty, Sensex Set for Subdued Start as Investors Await Global Cues

4 hours ago
karlach baldur's gate 3 character close-up

Baldur’s Gate 3 Turns One—But Karlach’s Mind Flayer Ending Still Haunts Fans

2 days ago
Reeve Collins Chinh Chu SPAC crypto M-3 Brigade Acquisition Wikimedia

Crypto Financiers Aim for $1 Billion SPAC to Build Digital Asset Treasury

2 days ago
WhatsApp advertising interface updates tab screen

Meta has finally flipped the switch: WhatsApp is now officially an ad platform

6 days ago
google pixel 10 pro fold leak render

Google Pixel 10 Pro Fold Could Be the First Foldable Phone With Full IP68 Rating

6 days ago
tel aviv stock exchange building

Israeli Stocks Hit Record Highs After U.S. Strikes on Iran Nuclear Sites

1 week ago
diljit dosanjh sardaar ji 3 film trailer poster

Sardaar Ji 3 Stirs the Pot: Diljit Dosanjh Confirms Hania Amir Stays, Film Heads for Overseas-Only Release

1 week ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

ADVERTISEMENTS

(adsbygoogle = window.adsbygoogle || []).push({});

POPULAR ARTICLES

eSports

Just How Big Will eSports Be?

8 years ago
Iontophoresis Device

Iontophoresis Device, the Best Treatment for Excessive Sweating

8 years ago
NOW Entertainment soon to Start Selling American Hustle82 Apparel

NOW Entertainment soon to Start Selling American Hustle82 Apparel

8 years ago
E-cigs Products in Classrooms

Is It Right to Ban the Juul and Other E-cigs Products in Classrooms?

8 years ago
Ryan Van Wagenen

Ryan Van Wagenen Expects Continued Growth for the Silicon Slopes

7 years ago
Working Remotely: Benefits for Employers and Employees

Working Remotely: Benefits for Employers and Employees

7 years ago
Benefits of installing Solar on your house

Benefits of installing Solar on your house

7 years ago
Casino Hacked using a Smart Thermometer

Casino Hacked using a Smart Thermometer

7 years ago
Ryan Van Wagenen Expands on Bitcoin, Ripple, and Investing in Other Cryptocurrency

Ryan Van Wagenen Expands on Bitcoin, Ripple, and Investing in Other Cryptocurrency

7 years ago
When Is The Right Time To Get A Logo For Your Business

When Is The Right Time To Get A Logo For Your Business?

7 years ago
Facebook Twitter Youtube

ABOUT US

The KeralaNews 24×7 website is for desi entertainment lovers across India, USA and UK. We often cover breaking News & Trending topics in India and have been referenced by numerous media outlets. Follow us on our Social media profiles for the latest updates and news.

Contents produced in this website are subjected to DigitalCopyRight Law.

© 2023 KeralaNews 24×7 – Website Designed by VISION

WEBSITE STATS

  • Google News Approved
  • 1,00,000 Traffic/Month
  • Domain Authority – 25
  • 70% Traffic from Google

ADVERTISE WITH US

If you are looking to advertise your business or website, feel free to contact us at ceo.keralanews247@gmail.com

We accept following form of advertisements,

  • Banner Ads
  • Contextual Links
  • Guest Posts
  • Sponsored Posts

SEARCH

No Result
View All Result

MORE INFO

  • ABOUT
  • PRIVACY
  • CONTACT
  • ADVERTISE

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL

© 2023 KeralaNews 24x7 - Website Designed by VISION

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.