As cited
Copy frozen at (site build).
threat intel
The Shelby Strategy
REF8685 used GitHub as a command and control (C2) infrastructure channel to evade traditional security defenses. The analysis examines how the threat actor leveraged the platform's legitimate features to maintain covert communications with compromised systems.
Why it matters: Security teams need to monitor GitHub for suspicious repository activity and C2 patterns, as legitimate platforms lower the friction for attackers to hide malicious traffic from perimeter defenses.
- Source published
- First seen by Cybersecurity Tracker