Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.
What does the Gitloker group demand from GitHub users?+
The Gitloker group wipes repositories and then extorts victims for their data, demanding a ransom. They claim to have created a backup using the compromised account and direct victims to contact them on Telegram.
What are the primary defensive measures against Gitloker attacks?+
Defenders should enforce multi-factor authentication (MFA), monitor GitHub audit logs for anomalous activities like mass deletions, and maintain regular, segregated backups of critical repositories on separate systems.