Cybercriminals Exploit GitHub’s Trusted Platform to Distribute Amadey Malware and Evade Security Filters


# Cybercriminals Exploit GitHub to Distribute Malware in Sophisticated Attack Campaigns

Cybercriminals are increasingly abusing legitimate platforms like GitHub to distribute malware, with recent campaigns demonstrating sophisticated techniques to evade detection and target organizations worldwide.

## GitHub-Based Malware Distribution

In April 2025, threat actors launched a campaign using fake GitHub accounts to host malicious payloads and distribute them through the Amadey malware-as-a-service (MaaS) platform. Cisco Talos researchers discovered that attackers created fraudulent GitHub repositories to bypass web filtering systems and simplify payload distribution.

The attack chain employs Emmenhtal (also known as PEAKLIGHT), a malware loader that delivers Amadey, which then downloads additional malicious payloads from attacker-controlled GitHub repositories. This campaign shares similarities with previous phishing attacks targeting Ukrainian entities using invoice-themed lures to distribute SmokeLoader.

### Key Malware Components

**Amadey** functions as both a downloader and information collector, capable of:
– Gathering system information from infected machines
– Loading DLL plugins for specific functions like credential theft and screenshot capture
– Delivering ransomware, including LockBit 3.0

**Emmenhtal** serves primarily as a payload downloader, though it lacks Amadey’s system information collection capabilities.

Researchers identified three GitHub accounts (Legendary99999, DFfe9ewf, and Milidmdds) hosting malicious content, including popular information stealers like Lumma Stealer, RedLine Stealer, and Rhadamanthys Stealer. GitHub has since removed these accounts.

## SquidLoader Targets Financial Institutions

Separately, Trellix security researchers uncovered a phishing campaign using SquidLoader malware to target financial services institutions in Hong Kong, with potential expansion to Singapore and Australia.

SquidLoader poses a significant threat due to its advanced evasion techniques:
– Anti-analysis and anti-sandbox capabilities
– Anti-debugging mechanisms
– Low detection rates by security tools
– Communication with remote servers for data exfiltration
– Deployment of Cobalt Strike beacons for remote access

## Evolving Social Engineering Tactics

Security researchers have identified numerous sophisticated social engineering campaigns employing diverse tactics:

### Invoice and Tax-Related Attacks
– **UNC5952 group**: Uses invoice-themed emails to deploy CHAINVERB downloader, ultimately installing ConnectWise ScreenConnect remote access software
– **Tax decoys**: Trick users into clicking malicious links disguised as PDF documents

### Government Impersonation
– **SSA-themed attacks**: Impersonate the U.S. Social Security Administration to harvest credentials and install trojanized remote access tools
– **Phone Link integration**: Instruct victims to sync Microsoft’s Phone Link app to intercept text messages and two-factor authentication codes

### Advanced Phishing Techniques
– **Logokit**: Creates convincing login page replicas hosted on AWS infrastructure with Cloudflare CAPTCHA integration
– **QR code campaigns**: Embed QR codes in PDF attachments directing users to credential harvesting pages
– **ClickFix tactics**: Deliver multiple malware families including Rhadamanthys Stealer and NetSupport RAT
– **SVG-based attacks**: Target B2B service providers using Scalable Vector Graphics files with embedded JavaScript for redirects

### Evasion Strategies
– **Cloaking-as-a-Service**: Platforms like Hoax Tech and JS Click Cloaker hide malicious websites from security scanners
– **Password-protected archives**: Bypass secure email gateways by preventing content scanning
– **HTML/JavaScript crafting**: Create realistic emails that evade traditional detection tools

## Key Statistics and Trends

According to Cofense research, QR codes appeared in 57% of advanced threat campaigns in 2024, highlighting their effectiveness in bypassing security measures. The widespread use of password-protected email attachments continues to challenge secure email gateway detection capabilities.

These campaigns demonstrate the evolving sophistication of cybercriminal operations, emphasizing the need for organizations to implement comprehensive security strategies that address both technical vulnerabilities and human factors in cybersecurity defense.

Share This Article