threat-intel
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Medium
Summary
Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfiltration. This activity involves automated scanners and leaked credentials, and defenders should focus on identifying anomalous user agent behavior and data exfiltration from private repositories.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data