Stargazer Goblin

Threat Actor updated 5 days ago (2024-11-29T13:46:22.424Z)
Download STIX
Preview STIX
Stargazer Goblin is a sophisticated malware entity that has been operating since August 2022. It has leveraged GitHub, a platform typically considered legitimate, to distribute various malware families, including Atlantida Stealer, Rhadamanthys infostealer, RisePro, Redline, and Lumma Stealer. This malicious actor created an elaborate network of ghost accounts across multiple platforms such as GitHub, Twitter, YouTube, Discord, Instagram, Facebook, and others, forming a robust Distribution as a Service (DaaS) model. Through this strategy, Stargazer Goblin bypasses suspicions of malicious activities, minimizes damage when GitHub disrupts their network, and swiftly recovers by updating broken links. The operation is strategically designed with different accounts serving distinct purposes: the first account updates phishing repositories with new links to active malicious releases, the second provides the image for phishing templates, while the third serves malware as a password-protected archive in a release. This structure allows Stargazer Goblin to quickly fix any broken links resulting from accounts or repositories being banned due to malicious activities. The total estimated profit for Stargazer Goblin from these activities is around $100,000. Notably, there were significant surges in activity on May 27, 2024, and May 31, 2024, with 621 and 555 instances respectively. These spikes suggest a possible campaign during those dates or a response to GitHub disrupting parts of Stargazer Goblin's operations. Furthermore, it is believed that the Atlantida Stealer campaigns, which targeted social media-oriented users, might have been executed by Stargazer Goblin to acquire accounts for the Ghost networks.
Description last updated: 2024-08-14T09:34:22.567Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Ghost is a possible alias for Stargazer Goblin. The "Ghost" malware, first discovered in 2020, is a sophisticated and successful malicious software that has been discreetly distributed via a network of GitHub accounts known as the Stargazers Ghost Network. This network utilizes open-source and legitimate software repositories to exploit trust and
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Facebook
Github
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Stargazer Goblin Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more