Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Indicators of Compromise
- domain: config.data
- domain: data-encoder.com
- domain: dccomicrat81.duckdns.org
- ip: 64.89.160.17
- domain: creainovada.xyz
- domain: consultanotificacionesjuridicas.site
- domain: simpmit.co
- url: http://creainovada.xyz/instructions/
- url: http://creainovada.xyz/instructions/Wscript.txt
- url: https://simpmit.co/
Still Circling: Inside the Operator Behind the GitHub Loader
Description
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader"]
- Adversary
- APT-C-36
- Pulse Id
- 6a9226b8695b02a09a6160ef
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainconfig.data | — | |
domaindata-encoder.com | — | |
domaindccomicrat81.duckdns.org | — | |
domaincreainovada.xyz | — | |
domainconsultanotificacionesjuridicas.site | — | |
domainsimpmit.co | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip64.89.160.17 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://creainovada.xyz/instructions/ | — | |
urlhttp://creainovada.xyz/instructions/Wscript.txt | — | |
urlhttps://simpmit.co/ | — |
Threat ID: 6a954eceacd9273b49e4922f
Added to database: 08/31/2026, 09:52:14 UTC
Last updated: 08/31/2026, 11:37:43 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.