Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

141–150 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#141
post #15

Earlier quoted context omitted.

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

How would Microsoft forge a DKIM signature? It sounds more likely that it's just a shitty email from Paypal.

Yes, they're originated by PayPal, but collected by a different original recipient and from there sent on to the victim. The envelope-recipient is not part of the material signed by DKIM, so the signature remains valid.

The To: header _is_ part of the signed material so will list the original recipient not the victim — but the attacker sets the recipient name/address to something misleading like “Order Received” to obscure this, and sets the store name to some long text that will be misleading when templated into the PayPal invoice request mail text.

PayPal have long had a problem with failing to make untrusted supplied text clear in their communications, but this is an unusually convincing attack.

I don't know why they always use (compromised?) onmicrosoft subdomains in particular. In the samples I've seen they're getting an SPF softfail so it doesn't seem MS's relays are passing SPF for paypal (sendgrid's might...)

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#143
post #134
post #65

Earlier quoted context omitted.

Yes. I use at least 2 of them... repo.or.cz, or rocketgit, and I guess they are many more. Drop microsoft github and move there or similar. But the best is to host yourself. But careful, you are going against big tech interests, expect their shadow-paid hackers to attack you and any real-life alternative you use.

Do you have any proof of these "shadow-paid hackers" or are you just schizo posting?

Big Tech companies are nearly the only beneficiaries of small hosting sabotage and since they are serial malpractice offenders, _they_ are to provide proof they aren't involved.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#144
post #88

I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will…

Bundling malware with keygens is a very common practice. It helps because the victim doesn’t suspect anything is wrong when the thing they downloaded appears to work, unlike the sham downloads in the linked article. Gives the attackers more time to exploit the system. You also need to look at the bigger picture: Keygens are something you very much do not want anywhere in a corporate environment for obvious reasons. B…

Then make it a flag for windows machines on a domain account or otherwise set to be a "business PC". Doing it on consumer systems is still a problem. A false positive flag for malware - or calling any keygen malware - is still a problem. It sholudn't be removing keygens from the system because they're keygens. You shouldn't have to add exceptions for them. If they actually contain malware, great, yes, please flag them. If they're not and it's my personal computer, then if I choose to download some cars, that's none of their business.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#145
post #88

I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will…

Windows Defender believes that my Rust egui application is a trojan, but magically if I compile it with a different toolchain it's no longer flagged :p

There's something seriously wrong with A/V heuristics.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#146
post #15
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

Fortunately, it's still pretty easy to filter these out. No idea why PayPal is ignoring this issue (I forward them to phishing@paypal.com hoping something will happen).

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#147
post #88

I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will…

Windows Defender believes that my Rust egui application is a trojan, but magically if I compile it with a different toolchain it's no longer flagged :p There's something seriously wrong with A/V heuristics.

Given Rust's supply chain worries, maybe it really is, don't count it out too quickly.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#148
post #116

This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?

The abuse reporting on GitHub completely sucks. You need to send a support ticket, which typically takes more than a month to get a reply to. And if by that time the comment or repo has been deleted they'll say "well it's deleted now, so we can't do anything". Because yes, I'm going to let spam sit around for over a month on my repo... :-/

Can't you just report it and hide it?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#149

Earlier quoted context omitted.

> going so far as to ban the accounts The responsible thing would be also to release all related data, icluding personal information (IP adresses, emails, list of contacts, chat logs) to investigation (police, etc)

I’m sure they report serious crimes and at least retain records for questionable activity. I don’t get visibility into internal Discord operations, though. We just see that the perpetrators lost both their Discord server and their accounts disappeared from other Discords they were in. They angrily returned later with new usernames.

> I’m sure they report serious crimes and at least retain records for questionable activity.

Why are you sure? I really doubt it.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#150
post #90

Earlier quoted context omitted.

I wasn't even talking about people who paid for a cert, just people signing up to try and help. They are generally more annoying then helpful to people who can do anything more than install and uninstall programs. Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead.

Amazon has an ask a question feature and it will email a lot of people who previously bought the product, not sure how it works. Anyway, I saw tons of responses from elderly people with nonsense answers like “I don’t know the answers please don’t email me”. People felt compelled to respond, now I see why Nigerian prince scams are so successful.

Also see Yahoo Answers, who got the gamification completely wrong (Stack Overflow later got it right). Users would answer "I don't know" to every question they saw, just to get a point for answering.
Post reply on HN