GitHub's 0% Response Rate: 29 Malware Accounts Still Active
- Patrick Duggan
- Dec 1, 2025
- 3 min read
Updated: Aug 11
TL;DR: We reported 29 malware-distributing GitHub accounts across 11 abuse reports. VirusTotal confirmed the payloads. OTX pulses documented the campaigns. GitHub suspended zero of them.
The Numbers
| Metric | Value | |--------|-------| | Reports Sent | 11 | | Accounts Reported | 29 (unique, excluding false positives) | | VT-Confirmed Malware | Yes (39/73, 47/76, 38/76 detection rates) | | Accounts Suspended | 0 | | Response Rate | 0% |
The Hall of Shame
APT-Level Infrastructure (Still Active)
• Created: July 27, 2016 (8+ years ago)
• C2 Channel: `github.com/getlook23/project1/issues/1`
• VT Detections: 39/73 (cryptbase.dll), 35/71 (LODCTR.DLL)
• OTX Documentation: "The case of getlook23: Using GitHub Issues as a C2"
• Status: STILL ACTIVE
A nation-state APT has been using GitHub Issues as a command-and-control channel for nearly a decade. Trend Micro published research on this in 2017. OTX has multiple pulses documenting it. The account is still up.
Malware Distribution Hubs (Still Active)
• 492 followers, 50 repos
• Dash Android Spyware (536 GitHub stars)
• Android-RATList, DDoS tools, GMailBomber
• Status: STILL ACTIVE
• 62 repos including:
• VT-confirmed malicious domains (15/95 detections)
• Status: STILL ACTIVE
• HALCYON-RAT with AV evasion features
• Payload builder, byte pumping for detection bypass
• Discord distribution channel
• Status: STILL ACTIVE
Cracked Malware Distribution (VT Confirmed)
• SHA256: `61974b843ae371e0472abf494817311e209d1ad9d01505537b7a58a330e19dda`
• VT Detection: 47/76
• Account age: 7 years (repurposed for malware in 2025)
• Status: STILL ACTIVE
Scam Infrastructure (Still Active)
• Active since 2016
• InstaBrute, FaceBrute, DDOSINC
• Status: STILL ACTIVE
• Telegram: @MIOBOMUIS
• Multiple drainer repos for sale
• Status: STILL ACTIVE
What We Reported
• VT hashes with 35-47+ vendor detections
• OTX pulse references with full IOC documentation
• MITRE ATT&CK technique mappings
• Account creation dates showing sleeper patterns
• Repo analysis showing malware distribution intent
The Pattern 38 Campaigns
• Created days before posting malware
• Zero repos, zero followers (sleeper pattern)
Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →
• Posted ZIPs containing Stealc/Rhadamanthys infostealers
• VT confirmed: 18+ detections per sample
GitHub's response: Nothing.
What This Means
1. GitHub Issues is a viable C2 channel - getlook23 proves you can run APT infrastructure on GitHub for 8+ years without action
2. Malware repos with 500+ stars persist - muneebwanee's Dash spyware has 536 stars. That's not low-visibility.
3. VT confirmation doesn't trigger action - We provided cryptographic proof. 47/76 vendors agree it's malware. GitHub disagrees by inaction.
4. Reporting is theater - [email protected] and [email protected] apparently forward to /dev/null
Our Response
• Document everything in our STIX feed
• Publish IOCs via OTX for the community
• Track account status for future reference
• Blog about it so the record exists
We're not going to stop reporting. But we're also not going to pretend it's working.
The Evidence
• `compliance/evidence/github-abuse-reports/*.json`
• Timestamps, account details, VT hashes, OTX references
• Full audit trail for anyone who wants to verify
Conclusion
GitHub's abuse response is either overwhelmed, understaffed, or simply not prioritizing malware distribution. When a Winnti APT C2 can operate for 8 years on your platform with public documentation, something is broken.
We'll keep reporting. We'll keep documenting. And we'll keep publishing the receipts.
*Reporter: DugganUSA LLC Threat Intelligence* *STIX Feed: https://analytics.dugganusa.com/api/v1/stix-feed* *OTX Profile: https://otx.alienvault.com/user/pduggusa*
*Accounts checked: December 1, 2025* *All 29 accounts verified active via GitHub API*
Get Free IOCs
Subscribe to our threat intelligence feeds for free, machine-readable IOCs:
AlienVault OTX: https://otx.alienvault.com/user/pduggusa
STIX 2.1 Feed: https://analytics.dugganusa.com/api/v1/stix-feed
Questions? [email protected]
The cheapest, fastest, most accurate threat feed on the internet.
275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=github-s-0-response-rate-29-malware-accounts-still-active




Comments