Stargazer Goblin

Malware updated 2 months ago (2024-08-14T10:18:05.760Z)
Download STIX
Preview STIX
Stargazer Goblin is a sophisticated malware entity that has been operating since August 2022. It has leveraged GitHub, a platform typically considered legitimate, to distribute various malware families, including Atlantida Stealer, Rhadamanthys infostealer, RisePro, Redline, and Lumma Stealer. This malicious actor created an elaborate network of ghost accounts across multiple platforms such as GitHub, Twitter, YouTube, Discord, Instagram, Facebook, and others, forming a robust Distribution as a Service (DaaS) model. Through this strategy, Stargazer Goblin bypasses suspicions of malicious activities, minimizes damage when GitHub disrupts their network, and swiftly recovers by updating broken links. The operation is strategically designed with different accounts serving distinct purposes: the first account updates phishing repositories with new links to active malicious releases, the second provides the image for phishing templates, while the third serves malware as a password-protected archive in a release. This structure allows Stargazer Goblin to quickly fix any broken links resulting from accounts or repositories being banned due to malicious activities. The total estimated profit for Stargazer Goblin from these activities is around $100,000. Notably, there were significant surges in activity on May 27, 2024, and May 31, 2024, with 621 and 555 instances respectively. These spikes suggest a possible campaign during those dates or a response to GitHub disrupting parts of Stargazer Goblin's operations. Furthermore, it is believed that the Atlantida Stealer campaigns, which targeted social media-oriented users, might have been executed by Stargazer Goblin to acquire accounts for the Ghost networks.
Description last updated: 2024-08-14T09:34:22.567Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Ghost is a possible alias for Stargazer Goblin. "Ghost" refers to a sophisticated malware network that was discovered and dismantled in 2020 following a two-year investigation led by Europol and global law enforcement agencies. The network, also known as the Stargazers Ghost Network, was found to be operating through GitHub accounts, distributing
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Facebook
Github
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Stargazer Goblin Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more