Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Security Week
  • Microsoft Says One Million Devices Impacted by Infostealer Campaign 
  • Security Week

Microsoft Says One Million Devices Impacted by Infostealer Campaign 

Ionut Arghire Published: March 7, 2025 | Updated: March 7, 2025 2 min read
0 views

Newly one million devices have been impacted by a malvertising campaign redirecting users to information stealer malware hosted on GitHub, Microsoft reports.

The campaign, attributed to a threat actor tracked as Storm-0408, targeted the visitors of illegal streaming websites, where malvertising redirectors led to an intermediate site and then to the Microsoft-owned code hosting platform.

The opportunistic attacks, which mainly relied on GitHub to host malware, but also on Discord and Dropbox, impacted “a wide range of organizations and industries, including both consumer and enterprise devices”, Microsoft says.

The multi-layers infection chain observed in these attacks included the GitHub-hosted first-stage payload acting as a dropper, second-stage files for system discovery and system information theft, and third-stage payloads for additional malicious activities.

Once installed on a victim’s device, the malware stored in GitHub repositories would fetch and deploy additional files and scripts, to harvest additional system information, achieve persistence, execute commands, and exfiltrate data from the compromised systems.

Specifically, Microsoft identified information stealers such as Lumma stealer and an updated version of Doenerium being deployed on victims’ systems, along with the NetSupport remote monitoring and management (RMM) software, and various PowerShell, JavaScript, VBScript, and AutoIT scripts.

For command-and-control (C&C) operations and data and browser credential exfiltration, the threat actors employed living-off-the-land binaries and scripts such as PowerShell, MSBuild, and RegAsm. For persistence, the attackers modified registry run keys and added a shortcut file to the Startup folder.

According to Microsoft, the first-stage payloads used in the campaign were digitally signed. Microsoft identified and revoked 12 different certificates used as part of the attacks.

Advertisement. Scroll to continue reading.

The tech giant has provided technical details on the observed malicious files and scripts, along with indicators of compromise (IoCs), urging organizations and users to ensure their systems are properly protected against such attacks.

Related: Network of 3,000 GitHub Accounts Used for Malware Distribution

Related: Threat Actors Abuse GitHub to Distribute Multiple Information Stealers

Related: US Transportation and Logistics Firms Targeted With Infostealers, Backdoors

Related: Threat Actor Uses Multiple Infostealers in Global Campaign

About The Author

Ionut Arghire

See author's posts

Original post here

What do you feel about this?

  • Security Week

Post navigation

Previous: Cyberattack Disrupts National Presto Industries Operations
Next: FBI: Fake Ransomware Attack Claims Sent to US Executives via Snail Mail 

Author's Other Posts

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers Cybersecurity_News-SecurityWeek.jpg

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

April 15, 2025 0 3
Kidney Dialysis Services Provider DaVita Hit by Ransomware ransomware.jpeg

Kidney Dialysis Services Provider DaVita Hit by Ransomware

April 15, 2025 0 0
Conduent Says Names, Social Security Numbers Stolen in Cyberattack Cybersecurity_News-SecurityWeek.jpg

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

April 15, 2025 0 0
2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches Cybersecurity_News-SecurityWeek.jpg

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

April 15, 2025 0 2

Related Stories

Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Ionut Arghire April 15, 2025 0 3
ransomware.jpeg
  • Security Week

Kidney Dialysis Services Provider DaVita Hit by Ransomware

Ionut Arghire April 15, 2025 0 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Ionut Arghire April 15, 2025 0 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Ionut Arghire April 15, 2025 0 2
VC-Funding_China-tech.jpg
  • Security Week

China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games

Associated Press April 15, 2025 0 0
Satellite-Link-Cybersecurity.jpg
  • Security Week

Blockchain, Quantum, and IoT Firms Unite to Secure Satellite Communications Against Quantum Threats

Kevin Townsend April 15, 2025 0 1

Trending Now

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does intruder.jpg 1

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 0 0
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts screen.jpg 2

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 0 0
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tel.jpg 3

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 0 0
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw nable.jpg 4

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 0 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does intruder.jpg 1
  • The Hacker News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 0 0
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts screen.jpg 2
  • The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 0 0
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tel.jpg 3
  • The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 0 0
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw nable.jpg 4
  • The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 0 0
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies chrome-cookies.jpg 5
  • The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

September 7, 2026 0 0
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication micro.jpg 6
  • The Hacker News

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

September 6, 2026 0 0
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner rev.jpg 7
  • The Hacker News

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

September 6, 2026 0 0

You may have missed

intruder.jpg
  • The Hacker News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

[email protected] The Hacker News September 7, 2026 0 0
screen.jpg
  • The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

[email protected] The Hacker News September 7, 2026 0 0
tel.jpg
  • The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

[email protected] The Hacker News September 7, 2026 0 0
nable.jpg
  • The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

[email protected] The Hacker News September 7, 2026 0 0
Copyright © 2026 All rights reserved. | MoreNews by AF themes.