The investigation traced a GitHub staging account to an email address that also appeared in a stealer log, confirming the operator’s workstation was compromised and exposing its files, browser history, and build artifacts. Those artifacts revealed a broader Blind Eagle-style operation involving RATs, phishing templates, bulk email tooling, crypters, and infrastructure across GitHub, DuckDNS, Bitbucket, AWS S3, and related services. #BlindEagle #AsyncRAT #DcRat #Remcos #XWorm #GitHub #DuckDNS #Bitbucket #AWS_S3
Keypoints
- The GitHub account cabeto850128 was linked to an email address revealed through commit metadata.
- The same email address appeared in an ALIEN TXTBASE stealer log and was independently confirmed by compromise intelligence as coming from an infected device named “Ghost.”
- The recovered workstation contained RAT folders, phishing templates, email-sending software, infrastructure records, and evidence of crypter/protector research.
- The phishing material impersonated Colombian judicial and traffic authorities and used password-protected archives as the delivery method.
- SendBlaster, SMTP relay testing, and browser history showed the operator was actively assembling and testing a bulk email delivery pipeline.
- The operator researched or used evasion tools such as FUD Crypter, MI6 Crypter, PolyCrypt, and Cassandra Protector.
- The operation used multiple staging and C2 locations, including GitHub, raw.githubusercontent.com, DuckDNS, Bitbucket, AWS S3, and creainovada[.]xyz.
MITRE Techniques
- [T1566.001 ] Phishing: Spearphishing Attachment – Used password-protected archives disguised as notices and documents to deliver payloads (‘judicial notification and traffic violation lures delivering password-protected archives’).
- [T1566.002 ] Phishing: Spearphishing Link – Victims were directed to actor-controlled domains that hosted payloads and lure pages (‘victims directed to actor-controlled phishing domains hosting payloads’).
- [T1583.001 ] Acquire Infrastructure: Domains – The actor registered and operated phishing and staging domains (‘registration and operation of phishing and staging domains’).
- [T1583.006 ] Acquire Infrastructure: Web Services – Legitimate services were abused for staging and distribution, including GitHub, Bitbucket, AWS S3, Discord, and Paste.ee (‘abuse of GitHub, Bitbucket, AWS S3, Discord, Paste.ee, and cloud-hosting platforms’).
- [T1568.003 ] Dynamic Resolution: DNS Calculation – DuckDNS was used for RAT command-and-control infrastructure (‘use of DuckDNS infrastructure for RAT C2’).
- [T1071 ] Application Layer Protocol – RAT communications used common web protocols for command and control (‘RAT communications conducted over common web protocols’).
- [T1105 ] Ingress Tool Transfer – Payloads and configuration files were retrieved from GitHub and other staging services (‘retrieval of payloads and configuration files from GitHub and other staging services’).
- [T1027 ] Obfuscated Files or Information – Base64-encoded PowerShell stages and crypters/protectors were used to hinder analysis (‘Base64-encoded PowerShell stages and use of crypters/protectors’).
- [T1036 ] Masquerading – Payloads were disguised as PDFs, archives, and legitimate-looking documents (‘payloads disguised as PDFs, archives, and legitimate-looking documents’).
- [T1218.004 ] System Binary Proxy Execution: InstallUtil – Execution abused InstallUtil.exe as a trusted Windows binary in the infection chain (‘execution chain abusing InstallUtil.exe as a trusted Windows binary’).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell – The multi-stage chain launched PowerShell commands during execution (‘multi-stage PowerShell execution observed in reconstructed infection chain’).
- [T1059.005 ] Command and Scripting Interpreter: Visual Basic – VBScript stages were delivered through SFX archives and used in execution (‘VBScript-based execution stages delivered through SFX archives’).
Indicators of Compromise
- [GitHub repositories ] staging and loader hosting – github[.]com/cabeto850128/comicsam, github[.]com/cabeto850128/jacobo
- [Raw content URLs ] payload and config delivery – raw.githubusercontent[.]com/cabeto850128/comicsam/…/kiSBJ4DDvg.pif, raw.githubusercontent[.]com/cabeto850128/comicsam/…/CdBhhfa.html
- [IP address ] prior staging infrastructure – 64.89.160[.]17
- [C2 domain ] RAT command-and-control – dccomicrat81[.]duckdns.org
- [Staging domain ] per-build payload hosting – creainovada[.]xyz
- [Alternate staging paths ] additional trusted-host delivery locations – bitbucket[.]org/adssgfdsg/testing/downloads/img_test.jpg, bbuseruploads.s3.amazonaws.com/…img_test.jpg
- [Phishing domains ] lure sites for judicial and traffic themes – consultanotificacionesjuridicas[.]site, simpmit[.]co
- [Malicious dropper sample ] SFX RAR/VBScript file – Ad20240730000024566F002152112200602430D-pdf.vbs