CrowdStrike, in collaboration with Google and Shadowserver, has dismantled a botnet known as Glassworm, which targeted open-source software developers. Over the past two years, this network deployed malware through developer accounts and code distribution channels to steal passwords and compromise over 300 GitHub repositories. The attackers used methods such as publishing malicious plugins, purchasing search ads to lure downloads, and taking over developer accounts with stolen credentials.
The operation severed four command-and-control channels, including those using the Solana blockchain and BitTorrent network, reducing the attackers' ability to deploy additional malware. This action comes amid a rise in supply chain attacks on open-source projects, with recent incidents affecting developers and projects globally. The report also noted a similar attack in March linked to North Korean hackers, underscoring the increasing focus on developer accounts as prime targets.
CrowdStrike and Google Dismantle Developer-Targeting Botnet
면책 조항: Phemex 뉴스에서 제공하는 콘텐츠는 정보 제공 목적으로만 제공됩니다. 제3자 기사에서 출처를 얻은 정보의 품질, 정확성 또는 완전성을 보장하지 않습니다.이 페이지의 콘텐츠는 재무 또는 투자 조언이 아닙니다.투자 결정을 내리기 전에 반드시 스스로 조사하고 자격을 갖춘 재무 전문가와 상담하시기 바랍니다.
