Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader
The investigation traced a GitHub staging account to an email address that also appeared in a stealer log, confirming the operator’s workstation was compromised and exposing its files, browser history, and build artifacts. Those artifacts revealed a broader Blind Eagle-style operation involving RATs, phishing templates, bulk email tooling, crypters, and infrastructure across GitHub, DuckDNS, Bitbucket, AWS S3, and related services. #BlindEagle #AsyncRAT #DcRat #Remcos #XWorm #GitHub #DuckDNS #Bitbucket #AWS_S3

Keypoints

  • The GitHub account cabeto850128 was linked to an email address revealed through commit metadata.
  • The same email address appeared in an ALIEN TXTBASE stealer log and was independently confirmed by compromise intelligence as coming from an infected device named “Ghost.”
  • The recovered workstation contained RAT folders, phishing templates, email-sending software, infrastructure records, and evidence of crypter/protector research.
  • The phishing material impersonated Colombian judicial and traffic authorities and used password-protected archives as the delivery method.
  • SendBlaster, SMTP relay testing, and browser history showed the operator was actively assembling and testing a bulk email delivery pipeline.
  • The operator researched or used evasion tools such as FUD Crypter, MI6 Crypter, PolyCrypt, and Cassandra Protector.
  • The operation used multiple staging and C2 locations, including GitHub, raw.githubusercontent.com, DuckDNS, Bitbucket, AWS S3, and creainovada[.]xyz.

MITRE Techniques

  • [T1566.001 ] Phishing: Spearphishing Attachment – Used password-protected archives disguised as notices and documents to deliver payloads (‘judicial notification and traffic violation lures delivering password-protected archives’).
  • [T1566.002 ] Phishing: Spearphishing Link – Victims were directed to actor-controlled domains that hosted payloads and lure pages (‘victims directed to actor-controlled phishing domains hosting payloads’).
  • [T1583.001 ] Acquire Infrastructure: Domains – The actor registered and operated phishing and staging domains (‘registration and operation of phishing and staging domains’).
  • [T1583.006 ] Acquire Infrastructure: Web Services – Legitimate services were abused for staging and distribution, including GitHub, Bitbucket, AWS S3, Discord, and Paste.ee (‘abuse of GitHub, Bitbucket, AWS S3, Discord, Paste.ee, and cloud-hosting platforms’).
  • [T1568.003 ] Dynamic Resolution: DNS Calculation – DuckDNS was used for RAT command-and-control infrastructure (‘use of DuckDNS infrastructure for RAT C2’).
  • [T1071 ] Application Layer Protocol – RAT communications used common web protocols for command and control (‘RAT communications conducted over common web protocols’).
  • [T1105 ] Ingress Tool Transfer – Payloads and configuration files were retrieved from GitHub and other staging services (‘retrieval of payloads and configuration files from GitHub and other staging services’).
  • [T1027 ] Obfuscated Files or Information – Base64-encoded PowerShell stages and crypters/protectors were used to hinder analysis (‘Base64-encoded PowerShell stages and use of crypters/protectors’).
  • [T1036 ] Masquerading – Payloads were disguised as PDFs, archives, and legitimate-looking documents (‘payloads disguised as PDFs, archives, and legitimate-looking documents’).
  • [T1218.004 ] System Binary Proxy Execution: InstallUtil – Execution abused InstallUtil.exe as a trusted Windows binary in the infection chain (‘execution chain abusing InstallUtil.exe as a trusted Windows binary’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – The multi-stage chain launched PowerShell commands during execution (‘multi-stage PowerShell execution observed in reconstructed infection chain’).
  • [T1059.005 ] Command and Scripting Interpreter: Visual Basic – VBScript stages were delivered through SFX archives and used in execution (‘VBScript-based execution stages delivered through SFX archives’).

Indicators of Compromise

  • [GitHub repositories ] staging and loader hosting – github[.]com/cabeto850128/comicsam, github[.]com/cabeto850128/jacobo
  • [Raw content URLs ] payload and config delivery – raw.githubusercontent[.]com/cabeto850128/comicsam/…/kiSBJ4DDvg.pif, raw.githubusercontent[.]com/cabeto850128/comicsam/…/CdBhhfa.html
  • [IP address ] prior staging infrastructure – 64.89.160[.]17
  • [C2 domain ] RAT command-and-control – dccomicrat81[.]duckdns.org
  • [Staging domain ] per-build payload hosting – creainovada[.]xyz
  • [Alternate staging paths ] additional trusted-host delivery locations – bitbucket[.]org/adssgfdsg/testing/downloads/img_test.jpg, bbuseruploads.s3.amazonaws.com/…img_test.jpg
  • [Phishing domains ] lure sites for judicial and traffic themes – consultanotificacionesjuridicas[.]site, simpmit[.]co
  • [Malicious dropper sample ] SFX RAR/VBScript file – Ad20240730000024566F002152112200602430D-pdf.vbs


Read more: https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader