Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, hacktivists, SheHacksPurple, threat modeling, education
Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Gitloker is a cyber threat actor targeting GitHub repositories through extortion schemes. The group compromises accounts using stolen credentials, wipes repository contents, and demands payments viaTelegram for their return. This targeted activity poses significant risks to organizations utilizingGitHub for software development.
Goals & Targeting
Gitloker's primary goal is financial gain through extortion. The actors target GitHub users across various sectors but have particularly focused on enterprises relying heavily onGitHub for code storage and collaboration.Gitloker's targeting profile appears geographicallyagnostic, as their attacks have been observed globally, impacting multiple industries. Their victims are typically organizations that cannot afford to lose critical developmental data, making them more likely to comply with ransom demands
Enhanced Description
Gitloker operates by infiltratingGitHub accounts, likely leveraging stolen credentials obtained from various sources.GitHub repositories are key targets, as the group steals data, creates fake backups, and deletes original content.Known to leave ransom notes in README files, Gitloker demands ransoms for the return of compromised data. The actors instruct victims to contact them via Telegram, a common communication tool among threat actors. Despite GitHub's efforts to mitigate such attacks,Gitloker continues to adapt their tactics, exploiting vulnerabilities within the platform. This group represents a growing trend of cybercriminals targeting cloud-based development tools and platforms to extort financial gains
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Gitloker has been active in increasingly sophisticated campaigns, leveraging the global network of developers on GitHub.As their methods involve wiping repositories and creating fake backups, Gitloker's campaign patterns suggest a focus on quick financial gains. Victims have included software companies, open-source projects, and consulting firms.The actors' operational tempo appears flexible, adapting to victim recovery efforts. Notable operations include multiple high-profile data exfiltrations from major tech firms.Past campaigns reveal a preference for encrypting or deleting files, making restoration challenging without their intervention
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low to medium confidence in Gitloker's exact motivations beyond financial gain; some TTPs are observed but specifics on targeted sectors/countries remain unclear. The group's toolset is inferred from their actions, not confirmed by evidence. Gaps exist in understanding their long-term goals and whether they operate independently or as part of a larger network.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
15
IOCs
0
Observed Data
0
Tactics