Ghost Accounts Abuse GitHub API in Mass Recon Campaign
2026-07-11T19:24:04Z•df636c4d086f3f77ab3e3e07eaaa2af471b76e2172fb7fbcd6d2ca8b07ac5ea1
ai-adversarialcryptographydata-breachdead-drop-resolverdestructive-malwareentra-idghost-accountsgithub-apigithub-repositoriesgo-modulehallu-squattinglegal-actionmalware-distributionmass-reconmicrosoft-365nation-state-activitypost-quantum-cryptographypowershellransomwareransomware-supportreconnaissanceremote-code-executionsocial-engineeringvishingwiper
What happened
SecurityWeek roundup covering multiple active threats and notable industry developments: attackers are creating ‘ghost’ GitHub accounts to abuse the GitHub API for large-scale recon of organizations (repositories and members), enabling targeted follow-on attacks. Separately, researchers report a network of ~200 malicious GitHub repositories (Go module -> PowerShell dead-drop resolver) used to deliver Windows malware, and the destructive GigaWiper backdoor combines wiper and ransomware capabilities. Other items include Okta-warning vishing campaigns targeting Microsoft 365/Entra ID, an adversar
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- df636c4d086f3f77ab3e3e07eaaa2af471b76e2172fb7fbcd6d2ca8b07ac5ea1
- Enrichment time
- 2026-07-11T19:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.