DiscoverCYFIRMA ResearchCYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN
CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN

CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN

Update: 2025-07-14
Share

Description

CYFIRMA Research's latest report explores a fake "Free VPN for PC" app hosted on GitHub, delivering a packed DLL payload using obfuscated Base64 hidden in junk strings. It uses P/Invoke to load a hidden DLL, executes GetGameData, and injects into legit processes like MSBuild.exe. Packed, evasive, and anti-debug.

Link to the Research Report: https://www.cyfirma.com/research/github-abused-to-spread-malware-disguised-as-free-vpn/

#MalwareAnalysis #CyberSecurity #DLLInjection #FakeVPN      #ReverseEngineering #CYFIRMA #CYFIRMAresearch #ETLM #ExternalThreatLandscapeManagement

https://www.cyfirma.com/

Comments 
loading
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN

CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN

CYFIRMA