Ghost Accounts Abuse GitHub API in Mass Recon Campaign

2026-07-11T19:24:04Zdf636c4d086f3f77ab3e3e07eaaa2af471b76e2172fb7fbcd6d2ca8b07ac5ea1
ai-adversarialcryptographydata-breachdead-drop-resolverdestructive-malwareentra-idghost-accountsgithub-apigithub-repositoriesgo-modulehallu-squattinglegal-actionmalware-distributionmass-reconmicrosoft-365nation-state-activitypost-quantum-cryptographypowershellransomwareransomware-supportreconnaissanceremote-code-executionsocial-engineeringvishingwiper

What happened

SecurityWeek roundup covering multiple active threats and notable industry developments: attackers are creating ‘ghost’ GitHub accounts to abuse the GitHub API for large-scale recon of organizations (repositories and members), enabling targeted follow-on attacks. Separately, researchers report a network of ~200 malicious GitHub repositories (Go module -> PowerShell dead-drop resolver) used to deliver Windows malware, and the destructive GigaWiper backdoor combines wiper and ransomware capabilities. Other items include Okta-warning vishing campaigns targeting Microsoft 365/Entra ID, an adversar

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
df636c4d086f3f77ab3e3e07eaaa2af471b76e2172fb7fbcd6d2ca8b07ac5ea1
Enrichment time
2026-07-11T19:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.