back to article Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank

Infosec researchers have discovered a network of over three thousand malicious GitHub accounts used to spread malware, targeting groups including gamers, malware researchers, and even other threat actors who themselves seek to spread malware. The research, penned by Antonis Terefos of Check Point Software, named the collection …

  1. Zolko Silver badge
    Pirate

    Writing malware you shall not

    That goblin looks a lot like an evil version of Master Yoda : was he a goblin ?

  2. Missing Semicolon Silver badge
    Devil

    Scripted rep/fork creation

    Should only be allowed by paid-for, verified accounts, and should be audited.

    I can think of no legitimate use for auth-creating repos and forks, except the generation of money for GitHub.

    Fixing this is easy, as long as you don't have revenue targets.

    1. Richard 12 Silver badge

      Re: Scripted rep/fork creation

      Banning it is easy.

      Enforcing said ban is quite difficult, as it's pretty easy to pretend to be a browser.

  3. Version 1.0 Silver badge
    Windows

    The Internet environmental evolution

    These days the Internet is a dangerous place to visit, not because all of the users are evil, but because so many of all our users don't do anything to avoid all the potential problems. And as we've seen recently, not every problem had been malware, a few have just been our updates ...

    We were slightly safer originally when we were only just reading newspapers, opening our mailed letters and writing replies, so the Internet environment needs to be made so much safer, not just "better" because every new feature has been a problem since the Internet appeared with malware everywhere. A new safe Internet environmental evolution is going to be a huge change, circumstances like the original evolution of rowing boats around the world, to these days (much safer) of flying airplanes everywhere.

    1. JessicaRabbit

      Re: The Internet environmental evolution

      Making the internet safe for the average plebian end user would mean unreasonable restrictions being placed on the rest of us.

  4. ChrisElvidge Silver badge

    ChatGPT

    I wonder whether these accounts have been ingested by OpenAI/Microsoft into ChatGPT data.

    1. Doctor Syntax Silver badge

      Re: ChatGPT

      Ingested? Don't discount the possibility it created them.

      1. Richard 12 Silver badge

        Re: ChatGPT

        How about both? Both is ... certain

  5. Anonymous Coward
    Anonymous Coward

    Maybe we should stop giving these groups cool names?

    Seems like that might serve as encouragement for getting noticed - "Hey, did you see the awesome name they gave us?" Maybe instead give them horrible names that they'd be ashamed to have associated with them. Things like "Latrine Diver" or "Weapons-Grade B.O."

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like