Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Stargazer Goblin

Also known as: 000 between 2022, 2024

Description

Stargazer Goblin surfaced around mid‑2022 as a financially motivated threat actor that monetises a GitHub‑based Distribution‑as‑a‑Service platform dubbed the "Ghost Network." Leveraging thousands of pseudo accounts, the group hosts malicious repositories that appear to be legitimate open‑source projects. The distribution payloads typically include HTA files, PowerShell scripts, and password‑protected archives which deploy popular infostealers – such as Atlantida Stealer, Rhadamanthys, Lumma Stealer, and RedLine – or custom backdoors like Ghost RAT and SectopRAT. The organization blends social engineering with supply‑chain compromise. Phishing templates targeted at developers, gamers, and financial users circulate in Discord channels and are delivered via shortened URLs (e.g., goo.su, bit.ly). Repository releases often masquerade as game mods for Minecraft or other popular projects, exploiting the trust community places in code‑hosting platforms. When GitHub blocks accounts or repositories, Stargazer Goblin promptly changes malicious links in its automated scripts to keep the delivery chain alive. Operationally, the actor injects PowerShell into legitimate processes such as regasm.exe using .NET injectors for lateral movement and exfiltrates stolen credentials over HTTP or DNS to remote C2 servers. The group also offers its DaaS service to other threat actors for a fee, generating significant revenue streams through both credential theft and ransomware‑related financial fraud. Because of its reliance on public code platforms and social media for initial infection vectors, Stargazer Goblin demonstrates high adaptability and persistence. Their campaigns span a wide array of sectors—including finance, media, defense, pharmaceuticals, mining, aviation, energy, healthcare, gaming, critical infrastructure, and utilities—within Brazil, Mexico, and the United States.

Goals & Targeting

Targeted Sectors

Financial services
Media
Defense
Pharmaceutical
Mining
Aviation
Energy
Healthcare
Gaming
Critical infrastructure
Utilities

Targeted Countries / Regions

BR
MX
US

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 hour ago

Executive Summary

Stargazer Goblin is a financially‑motivated cybercrime group that operates a large Distribution‑as‑a‑Service (DaaS) network on GitHub, using thousands of automated "ghost" accounts to host and update malware delivery repositories. They combine low‑cost phishing campaigns—particularly on Discord—with supply‑chain abuse of legitimate code hosting to deliver infostealers such as Atlantida Stealer, Rhadamanthys, Lumma Stealer, RedLine, and custom backdoors like Ghost RAT. The actor’s rapid link updates and cross‑platform social engineering keep the operation resilient and profitable, earning an estimated $100 k between 2022 and 2024.

Goals & Targeting

Stargazer Goblin’s strategic objectives revolve around maximizing monetary gain through credential theft and opportunistic ransomware or banking fraud. The group deliberately targets sectors where sensitive credentials can be leveraged for high‑value transactions and where supply‑chain weaknesses are common. Individuals in developer or gaming communities are targeted with spearphishing links, while enterprise users in critical infrastructure are approached via legitimate code repositories masquerading as useful libraries or mod clients. By blending phishing, social engineering, and supply‑chain abuse, the actor seeks to breach high‑profile accounts across Brazil, Mexico, and the United States.

Enhanced Description

Key Capabilities

  • Distributes malware through public code repositories on GitHub as a Service
  • Uses phishing templates posted in Discord channels for initial access
  • Rapidly updates malicious links after account or repository bans to maintain continuity
  • Employs Ghost accounts and automated account creation to reduce detection risk
  • Shares malicious links across multiple social platforms (GitHub, Twitter, YouTube, Discord, Instagram, Facebook)
  • Deploys victim‑oriented phishing templates targeting specific user profiles
  • Leverages supply‑chain abuse by hosting malware in legitimate‑looking releases
  • Injects PowerShell scripts into legitimate processes for lateral movement
  • Exfiltrates stolen data over HTTP or DNS to remote C2 servers

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Discovery
Exfiltration
Resource Development

ATT&CK Techniques

T1071.004
T1566.002
T1566.001
T1133
T1082
T1190
T1055
T1059
T1102
T1098.001
T1204
T1041
T1059.001
T1078
T1027
T1059.003
T1189
T1071.001
T1105
T1078.004
T1566.003

Software / Tooling

Atlantida Stealer
Rhadamanthys
RisePro
Lumma Stealer
RedLine
GO Downloader
SectopRAT
Vidar
Cobeacon

Campaigns & Victims

Stargazer Goblin’s campaigns exhibit a high operational tempo, with frequent updates to malicious links and repositories when blocked. Using an automated DaaS network on GitHub, the actor has enabled thousands of dropper repos that stay functional through rapid link rotation. Victims have ranged from individual developers and gamers to enterprise users in finance, health, critical infrastructure, and other high‑value sectors across Brazil, Mexico, and the United States. The group's revenue reports (over $100 k between 2022‑24) indicate a profitable supply‑chain model where the actor also sells access or malware bundles to other adversaries. Notable operations include a 2024 campaign that distributed a GO downloader via thousands of seemingly legitimate GitHub projects and used Discord phishing templates for initial infection. Operations remain persistent due to continuous repository renewal, use of ghost accounts, and cross‑platform social engineering.

IOC Patterns

  • malicious file hash
  • domain name hosting malicious payloads
  • IP address used as C2
  • URL pointing to a malicious GitHub repository
  • phishing template link posted on Discord
  • GitHub repository URL containing "page" path pattern
  • ghost account identifiers across social media platforms

Recommended Actions

  • Monitor and block known malicious GitHub repositories that host phishing templates or malware drops
  • Implement controls to detect rapid changes in URLs within repositories, triggering alerts
  • Alert security teams about spearphishing messages originating from Discord channels or other social platforms
  • Block traffic to malicious Go downloader distribution repositories on GitHub
  • Filter or block domains containing suspicious path patterns such as 'page' used for malicious links
  • Identify and flag Ghost account activity across social media to prevent user interaction with them
  • Deploy endpoint protection capable of detecting and quarantining known malware families (SectopRAT, Vidar, Cobeacon) and their downloader components
  • Educate users on spearphishing risks tied to seemingly legitimate code repositories
  • Enforce multi‑factor authentication for cloud accounts to mitigate credential reuse

Suggested Tags

Stargazer Goblin
GitHub DaaS
Phishing
Stealer Malware
Cryptocurrency Theft
Ghost Accounts
Distributed Link Distribution as a Service
GO Downloader
Atlantida Stealer
Rhadamanthys
RedLine
SectopRAT

Confidence Assessment

The information on Stargazer Goblin is drawn from multiple public intelligence sources, providing credible evidence of their use of GitHub DaaS, phishing via Discord, and deployment of infostealers. While the financial impact ($100 k revenue estimate) and exact operational timelines are inferred rather than directly verified, the consistent pattern across reports supports a high confidence assessment of the actor’s motivations, capabilities, and sector targeting. Gaps remain regarding precise attribution—no confirmed internal or external evidence linking the group to a specific nation or organization—and detailed insight into their internal command‑and‑control architecture beyond public-facing repositories.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 Domain 9 URL 5 IPv4 Address 1 SHA-256 Hash 1

References

Intel Summary

25

Techniques

89

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

Ransomware
APT
malware_distribution
stealing
financial_sector
cybercrime
Stargazer Goblin
GitHub Malware Distribution
HTA Exploitation
DaaS
Fake Accounts
Infostealer
Cybercriminal
Distribution-as-a-Service
Gaming cheats
Backdoor
Stealer
Malware Distribution Network
credential-theft
GitHub-abuse
malicious-website-distribution
mass-account-lab
Social Engineering
Ghost Accounts
phishing
password_protected_archive
hta_malware
wordpress_compromise
vbscript
powershell
process-injection
regasm
crypto_mining
URL shortener abuse
Multi-Malware Deployment
Initial Access via Web
Command and Control over HTTP
GitHub compromised accounts
phishing link
GitHub DaaS
Phishing
Stealer Malware
Cryptocurrency Theft
Distributed Link Distribution as a Service
GO Downloader
Atlantida Stealer
Rhadamanthys
RedLine
SectopRAT

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.