As cited
Copy frozen at (site build).
threat intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs identified multiple coordinated campaigns systematically enumerating GitHub organizations, repositories, and user accounts via the GitHub API. The attackers use automated scraping tools with legitimate-appearing user agents and leverage dormant ghost accounts or compromised OAuth tokens to avoid detection while conducting reconnaissance.
Why it matters: Any organization with public or private GitHub repositories faces reconnaissance risk from attackers mapping corporate structures and code repositories; security teams should review GitHub API access logs and monitor for unusual enumeration patterns.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs identified multiple campaigns using automated tools to enumerate corporate GitHub organizations, repositories, and user accounts via the GitHub application programming interface (API). Attackers employ dormant or ghost accounts that may be years old, as well as compromised OAuth tokens and personal access tokens, to blend reconnaissance activity into normal traffic.
Why it matters: Development teams and security operations centers (SOCs) should audit GitHub organization member access and review API activity logs for signs of enumeration, as reconnaissance precedes initial access attempts and data theft in supply chain attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs identified multiple campaigns using automated tools to enumerate corporate GitHub organizations, repositories, and user accounts via the GitHub application programming interface (API). Attackers employ dormant or ghost accounts that may be years old, as well as compromised OAuth tokens and personal access tokens, to blend reconnaissance activity into normal traffic.
Why it matters: Development teams and security operations centers (SOCs) should audit GitHub organization member access and review API activity logs for signs of enumeration, as reconnaissance precedes initial access attempts and data theft in supply chain attacks.
- Source published
- First seen by Cybersecurity Tracker