Also known as: 000 between 2022, 2024
Stargazer Goblin surfaced around mid‑2022 as a financially motivated threat actor that monetises a GitHub‑based Distribution‑as‑a‑Service platform dubbed the "Ghost Network." Leveraging thousands of pseudo accounts, the group hosts malicious repositories that appear to be legitimate open‑source projects. The distribution payloads typically include HTA files, PowerShell scripts, and password‑protected archives which deploy popular infostealers – such as Atlantida Stealer, Rhadamanthys, Lumma Stealer, and RedLine – or custom backdoors like Ghost RAT and SectopRAT. The organization blends social engineering with supply‑chain compromise. Phishing templates targeted at developers, gamers, and financial users circulate in Discord channels and are delivered via shortened URLs (e.g., goo.su, bit.ly). Repository releases often masquerade as game mods for Minecraft or other popular projects, exploiting the trust community places in code‑hosting platforms. When GitHub blocks accounts or repositories, Stargazer Goblin promptly changes malicious links in its automated scripts to keep the delivery chain alive. Operationally, the actor injects PowerShell into legitimate processes such as regasm.exe using .NET injectors for lateral movement and exfiltrates stolen credentials over HTTP or DNS to remote C2 servers. The group also offers its DaaS service to other threat actors for a fee, generating significant revenue streams through both credential theft and ransomware‑related financial fraud. Because of its reliance on public code platforms and social media for initial infection vectors, Stargazer Goblin demonstrates high adaptability and persistence. Their campaigns span a wide array of sectors—including finance, media, defense, pharmaceuticals, mining, aviation, energy, healthcare, gaming, critical infrastructure, and utilities—within Brazil, Mexico, and the United States.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Stargazer Goblin is a financially‑motivated cybercrime group that operates a large Distribution‑as‑a‑Service (DaaS) network on GitHub, using thousands of automated "ghost" accounts to host and update malware delivery repositories. They combine low‑cost phishing campaigns—particularly on Discord—with supply‑chain abuse of legitimate code hosting to deliver infostealers such as Atlantida Stealer, Rhadamanthys, Lumma Stealer, RedLine, and custom backdoors like Ghost RAT. The actor’s rapid link updates and cross‑platform social engineering keep the operation resilient and profitable, earning an estimated $100 k between 2022 and 2024.
Goals & Targeting
Stargazer Goblin’s strategic objectives revolve around maximizing monetary gain through credential theft and opportunistic ransomware or banking fraud. The group deliberately targets sectors where sensitive credentials can be leveraged for high‑value transactions and where supply‑chain weaknesses are common. Individuals in developer or gaming communities are targeted with spearphishing links, while enterprise users in critical infrastructure are approached via legitimate code repositories masquerading as useful libraries or mod clients. By blending phishing, social engineering, and supply‑chain abuse, the actor seeks to breach high‑profile accounts across Brazil, Mexico, and the United States.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Stargazer Goblin’s campaigns exhibit a high operational tempo, with frequent updates to malicious links and repositories when blocked. Using an automated DaaS network on GitHub, the actor has enabled thousands of dropper repos that stay functional through rapid link rotation. Victims have ranged from individual developers and gamers to enterprise users in finance, health, critical infrastructure, and other high‑value sectors across Brazil, Mexico, and the United States. The group's revenue reports (over $100 k between 2022‑24) indicate a profitable supply‑chain model where the actor also sells access or malware bundles to other adversaries. Notable operations include a 2024 campaign that distributed a GO downloader via thousands of seemingly legitimate GitHub projects and used Discord phishing templates for initial infection. Operations remain persistent due to continuous repository renewal, use of ghost accounts, and cross‑platform social engineering.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information on Stargazer Goblin is drawn from multiple public intelligence sources, providing credible evidence of their use of GitHub DaaS, phishing via Discord, and deployment of infostealers. While the financial impact ($100 k revenue estimate) and exact operational timelines are inferred rather than directly verified, the consistent pattern across reports supports a high confidence assessment of the actor’s motivations, capabilities, and sector targeting. Gaps remain regarding precise attribution—no confirmed internal or external evidence linking the group to a specific nation or organization—and detailed insight into their internal command‑and‑control architecture beyond public-facing repositories.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
89
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics