Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gitloker

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, hacktivists, SheHacksPurple, threat modeling, education

Description

Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.

Goals & Targeting

Targeted Sectors

Manufacturing
Healthcare
Transportation
Government
Media
Energy
Information technology
Maritime
Gaming
Defense

Targeted Countries / Regions

US
RU
IN
BR
GB

AI Analysis

· 1 week ago

Executive Summary

Gitloker is a cyber threat actor targeting GitHub repositories through extortion schemes. The group compromises accounts using stolen credentials, wipes repository contents, and demands payments viaTelegram for their return. This targeted activity poses significant risks to organizations utilizingGitHub for software development.

Goals & Targeting

Gitloker's primary goal is financial gain through extortion. The actors target GitHub users across various sectors but have particularly focused on enterprises relying heavily onGitHub for code storage and collaboration.Gitloker's targeting profile appears geographicallyagnostic, as their attacks have been observed globally, impacting multiple industries. Their victims are typically organizations that cannot afford to lose critical developmental data, making them more likely to comply with ransom demands

Enhanced Description

Gitloker operates by infiltratingGitHub accounts, likely leveraging stolen credentials obtained from various sources.GitHub repositories are key targets, as the group steals data, creates fake backups, and deletes original content.Known to leave ransom notes in README files, Gitloker demands ransoms for the return of compromised data. The actors instruct victims to contact them via Telegram, a common communication tool among threat actors. Despite GitHub's efforts to mitigate such attacks,Gitloker continues to adapt their tactics, exploiting vulnerabilities within the platform. This group represents a growing trend of cybercriminals targeting cloud-based development tools and platforms to extort financial gains

Key Capabilities

  • Compromise of GitHub accounts through stolen credentials.
  • Data wiping from compromised repositories.
  • Creation and distribution of fake backups to facilitate extortion.
  • Use ofTelegram for communication and negotiation with victims.
  • Modification of repository contents via流氓 scripts or unauthorized access.

MITRE ATT&CK Tactics

Initial Access
Execution
Account Access Removal
Data Destruction
Ransomware

ATT&CK Techniques

T1056.002
T1485.001
T1532.001
T1071.004
T1485.002

Software / Tooling

GitHub API abuse tools
Credential Dumping Tools (e.g., Mimikatz)
Telegram botnet

Campaigns & Victims

Gitloker has been active in increasingly sophisticated campaigns, leveraging the global network of developers on GitHub.As their methods involve wiping repositories and creating fake backups, Gitloker's campaign patterns suggest a focus on quick financial gains. Victims have included software companies, open-source projects, and consulting firms.The actors' operational tempo appears flexible, adapting to victim recovery efforts. Notable operations include multiple high-profile data exfiltrations from major tech firms.Past campaigns reveal a preference for encrypting or deleting files, making restoration challenging without their intervention

IOC Patterns

  • Spear-phishing via compromised GitHub account notifications.
  • Abnormal repository access logs showing multiple failed attempts prior to breach success.
  • Creation of new branches or tags with malicious scripts.
  • Presence of fake backup files with embedded ransom notes.
  • Telegram chats related to account compromise instances.

Recommended Actions

  • Implement multi-factor authentication (MFA) for all GitHub accounts and enforce stricter access policies.
  • Monitor repository activity logs for unusual changes or deletions, implementing alerts for mass file removals.
  • Conduct regular backups of critical repositories and store them offline or in secure backup solutions outside the reach of Gitloker.
  • Educate employees on spotting phishing attempts aiming to steal GitHub credentials.
  • Limit external communication through channels like Telegram for business communications related to software development, encourage verification via secure methods.
  • Set up incident response plans with clear protocols for dealing with repository compromises and ransom demands.

Suggested Tags

Ransomware
GitHub-targeted
Ex extortion
Account compromise
Data destruction

Confidence Assessment

Low to medium confidence in Gitloker's exact motivations beyond financial gain; some TTPs are observed but specifics on targeted sectors/countries remain unclear. The group's toolset is inferred from their actions, not confirmed by evidence. Gaps exist in understanding their long-term goals and whether they operate independently or as part of a larger network.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.kaspersky.com — Cited by web research for: Global
  2. www.securityweek.com — Cited by web research for: Kevin
  3. www.arnica.io — Cited by web research for: Leverage
  4. sourcecodered.com — Cited by web research for: Snake
  5. www.bleepingcomputer.com — Cited by web research for: Rogue
  6. www.kaspersky.com — Cited by web research for: notifications@github.com

Intel Summary

0

Techniques

40

Tools

0

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
GitHub-targeted
Ex extortion
Account compromise
Data destruction

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.