Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Chinese malware is flooding GitHub pages – HiddenGh0st, Winos and kkRAT hit devs via SEO poisoning

Tech Wavo by Tech Wavo
September 16, 2025
in Computers
0




  • Chinese users are being targeted by malware campaigns using spoofed download sites and SEO poisoning
  • kkRAT features advanced capabilities including clipboard hijacking, remote monitoring, and antivirus evasion
  • Attackers exploited GitHub Pages to host phishing sites

Chinese users looking to download popular browsers and communications software are being targeted by different malware variants, granting attackers remote access capabilities. This is according to multiple cybersecurity organizations, including Fortinet FortiGuard Labs, and Zscaler ThreatLabz.

The former discovered an SEO poisoning campaign to deliver two Remote Access Trojans (RAT) – HiddenGh0st, and Winos – both variants of the infamous Gh0st RAT.

In the campaign, the threat actors created spoofed download pages for programs such as DeepL Translate, Google Chrome, Signal, Telegram, WhatsApp, and WPS Office, on typosquatted domains.


You may like

Stealing crypto and disabling AV

They then manipulated search rankings using different SEO plugins to trick people searching for these programs into visiting the wrong sites. The download seemingly deploys the wanted program, but the installer is trojanized, also serving one of the above-mentioned trojans.

At the same time, researchers from Zscaler observed a previously unknown trojan, called kkRAT, being disseminated. This campaign started in May this year and also includes Winos and FatalRAT.

kkRAT’s code is similar to that of Gh0st RAT and Big Bad Wolf, Zscaler explained: “kkRAT employs a network communication protocol similar to Ghost RAT, with an added encryption layer after data compression. The RAT’s features include clipboard manipulation to replace cryptocurrency addresses and the deployment of remote monitoring tools (i.e. Sunlogin, GotoHTTP).”

It is also capable of killing antivirus software before running any malicious activity, to better hide its presence. Among the AV solutions targeted by the trojan are 360 Internet Security suite, 360 Total Security, HeroBravo System Diagnostics suite, and others.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Unlike Fortinet’s discovery, in this campaign the phishing sites are hosted on GitHub pages, leaning into the trust that the platform enjoys with its community to distribute the trojans. The GitHub account used in this campaign has since been terminated.

Via The Hacker News

You might also like

Previous Post

Walmart is selling a $479 under-desk treadmill for $170 that's 'compact, modern, and functional'

Next Post

Flock Safety Claims It Can Rid The US Of Crime, Even As Cities Rid Themselves Of Flock

Next Post
This Week In Techdirt History: August 3rd – 9th

Flock Safety Claims It Can Rid The US Of Crime, Even As Cities Rid Themselves Of Flock

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

IPTV piracy network traced by researchers ran for years across 1,000 domains and 10,000 IPs

by Tech Wavo
September 16, 2025
0
IPTV piracy network traced by researchers ran for years across 1,000 domains and 10,000 IPs
Computers

Silent Push uncovers IPTV piracy network spanning thousands of domains and addresses worldwidePiracy network linked to multiple companies impacts global...

Read more

Snap OS 2.0 Hands-On: 3 Things I Love and 1 Thing I Hate

by Tech Wavo
September 16, 2025
0
Snap OS 2.0 Hands-On: 3 Things I Love and 1 Thing I Hate
Mobile

Snap, the social media company turned AR glasses-maker, has officially announced Snap OS 2.0, its next generation of smart glasses...

Read more

Flock Safety Claims It Can Rid The US Of Crime, Even As Cities Rid Themselves Of Flock

by Tech Wavo
September 16, 2025
0
This Week In Techdirt History: August 3rd – 9th
Technology

from the high-on-their-own-supply dept Even if you truly believe the company you work for is capable of doing this, perhaps...

Read more

Chinese malware is flooding GitHub pages – HiddenGh0st, Winos and kkRAT hit devs via SEO poisoning

by Tech Wavo
September 16, 2025
0
Chinese malware is flooding GitHub pages – HiddenGh0st, Winos and kkRAT hit devs via SEO poisoning
Computers

Chinese users are being targeted by malware campaigns using spoofed download sites and SEO poisoningkkRAT features advanced capabilities including clipboard...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock