Gitloker targets GitHub repositories by wiping contents and extorting victims via Telegram.
Analyst brief
The Gitloker group targets GitHub repositories by wiping their contents and extorting victims for the data. They use stolen credentials to compromise accounts, claim to have created a backup, and direct victims to contact them on Telegram, leaving a ransom note as a README file. Primary TTPs include credential theft, repository wiping, and ransomware-style extortion; no specific malware tools are detailed. Defenders should enforce multi-factor authentication (MFA), monitor GitHub audit logs for anomalous activities like mass deletions, and maintain segregated backups of critical repositories.
Gitloker
unknown
Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.
What does the Gitloker group demand from GitHub users?+
The Gitloker group wipes repositories and then extorts victims for their data, demanding a ransom. They claim to have created a backup using the compromised account and direct victims to contact them on Telegram.
What are the primary defensive measures against Gitloker attacks?+
Defenders should enforce multi-factor authentication (MFA), monitor GitHub audit logs for anomalous activities like mass deletions, and maintain regular, segregated backups of critical repositories on separate systems.