MEDIUMMalware
Global
GitHub Used as Covert Channel in Multi-Stage Malware Campaign
Thursday, April 2, 2026 at 01:00 PM UTC·Source: Infosecurity Magazine
Updated: Thursday, April 2, 2026 at 05:46 PM UTC
Executive Summary
LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration
Analysis
LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration