threat-intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Medium
Summary
Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a company's GitHub activity, including cloning private repositories. The tactic involves using a coordinated network of 'ghost' accounts to avoid detection and blend in with normal API usage.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
