Living off GitHub: From Gmail Reply-Baiting to Fileless Exfiltration
2026-08-24 • DSLU •
https://dslua.org/publications/living-off-github-from-gmail-reply-baiting-to-fileless-exfiltration/
Attackers targeted a Ukrainian civil society representative with a personalized collaboration email sent from a genuine Gmail account, withholding the malicious link until the recipient replied. A Codeberg-hosted archive contained an LNK file disguised as a PDF, which displayed a benign decoy while downloading scripts from GitLab and executing the next stage in memory. The malware established scheduled-task persistence, collected system details and Downloads-folder listings, and exfiltrated the data through the GitHub API. DSLU also identified tooling for Telegram data collection and AnyDesk deployment, along with logs naming more than 45 compromised computers.