Massive Malware Attack Infects 1 Million Devices via GitHub - Stay Safe!

Microsoft has uncovered a large-scale malware attack, named Storm-0408, that infected nearly one million devices worldwide. The attackers used malvertising on illegal streaming sites to spread malware hosted on GitHub, Discord, and Dropbox. The malware stole personal data, browser credentials, and even disabled security protections.
- Malvertising Trick: Users watching pirated videos were unknowingly redirected to malicious websites.
- GitHub Exploited: Attackers hosted and delivered malware from GitHub repositories.
- Multi-Stage Attack: The malware collected system details, installed stealers like Lumma and Doenerium, and used PowerShell scripts to disable security.
- Browser Data Theft: Chrome, Edge, and Firefox credentials were stolen, putting victims at risk.
- Microsoft's Response: The infected GitHub repositories were removed, and security guidelines were issued.
This attack shows the dangers of pirated websites and the growing use of malvertising to spread malware. Users should avoid illegal streaming sites, keep security software updated, and enable multi-factor authentication (MFA) to stay protected. Cybercriminals continue to find new ways to spread malware, making online vigilance more important than ever.
Comment(s)
Categories
- Other (42)
- Ransomware (153)
- Events and News (27)
- Features (45)
- Security (481)
- Tips (79)
- Google (25)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (48)
- Malware Alerts (223)
- Cyber Attack (276)
- Data Backup (12)
- Data Breach (112)
- Phishing (161)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (16)
- Updates (4)
- Alert (71)
- Hacking (60)
- Social Media (8)
- vulnerability (63)
- Hacker (33)
- Spyware (11)
- Windows (7)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (7)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (8)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (17)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (5)
Recent Posts
Archive
Tags
cyber attack
phishing
phishing attacks
data breach
malware
ransomware
cyber threats
cybersecurity
phishing attack
ransomeware
data theft
android malware
phishingattack
data protection
cyberthreats
financial security
cyber security
cyber fraud
cybercrime
credential theft
cybersecurity threats
network security
phishing scam
cert-in
ddos attack
data stealing
financial fraud
phishing email
microsoft
cyberattack
net protector total security
financial crime
critical vulnerability
ddos
twitter
fraud protector
india
cyber crime
hacking
data security
cybercriminals
trojan
cyber threat
lockbit
cyber attacks
cyber scam
online fraud
fraudalert
scam
vulnerability