Cyber Security News

Developers Beware! Hackers Using Fake Job Offers to Attack Developers

Hackers have been targeting developers by using fake job offers to hijack GitHub accounts.

This alarming trend has raised significant concerns among corporate information security teams, especially since developers often have administrative access to critical repositories.

The attack begins with an email that appears to be from GitHub, offering an attractive job position with a $180,000 annual salary and generous benefits.

The phishing email from GitHub with a job offer

The emails are sent from notifications@github.com, a legitimate GitHub address, which makes them appear authentic, as per a report by Kaspersky.

However, there are subtle red flags, such as the use of a notification address for HR communications and email subjects that do not match the job offer content.

Despite these discrepancies, the promise of a lucrative salary entices some recipients to click the link provided.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Phishing Career Site on GitHub

Clicking the link directs the recipient to a fake GitHub career site, using addresses like githubtalentcommunity[.]online and githubcareers[.]online.

These phishing sites have since been taken down, but not before causing significant damage. On the fake site, developers are prompted to log in to their GitHub account and authorize a new OAuth application.

Phishing career site on GitHub

This malicious OAuth application requests extensive permissions, including access to private repositories, personal data, and the ability to delete repositories.

Another variant of the phishing email claims that GitHub has been hacked and requires the user’s authorization to mitigate the consequences. Both tactics aim to trick developers into granting dangerous permissions.

The Next Thing: Repository Wipe and Ransom Demand

If a developer falls for the scam and authorizes the malicious OAuth application, the attackers quickly exploit the granted permissions.

They wipe all the victim’s repositories and rename them, leaving behind only a README.me file.

Hijacked repositories on GitHub

The README.me file contains a ransom note, stating that the data has been compromised but a backup exists.

To restore the data, the victim is instructed to contact a Gitloker user on Telegram.

These phishing emails are sent using the GitHub discussion system, leveraging already compromised accounts to tag multiple users, who then receive emails from the legitimate GitHub address.

How to Protect Against Such Attacks on GitHub Accounts

To safeguard against these sophisticated phishing attacks, developers should follow these recommendations:

  1. Scrutinize Email Details: Always check the details of an email, including the subject, text, and sender address. Discrepancies are likely signs of phishing.
  2. Avoid Clicking Suspicious Links: If you receive a suspicious email from GitHub, do not click any links. Report the email to GitHub support.
  3. Be Cautious with OAuth Applications: Never authorize unknown OAuth applications. Regularly review and remove any suspicious applications from your GitHub account.

By staying vigilant and following these guidelines, developers can protect their accounts and prevent potential data breaches.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago