Comment on GitHub projects targeted with malicious commits to frame researcher

TWeaK@lemm.ee ⁨3⁩ ⁨days⁩ ago

When accessed by BleepingComputer, however, the link returned a 404 (Not Found), and according to several others who tried to access the URL, no content ever existed at the location from the beginning.

This really doesn’t mean anything, it’s not unheard of for malicious actors to not set up their C&C servers until later on. This has actually been exploited by law enforcement in other cases also, they simply registered the domain themselves and took control away ahead of the attacker.

There’s a risk with setting up the C&C that it could be traced back to the attackers. By not setting it up until it’s needed you avoid that risk until it becomes necessary.

source
Sort:hotnewtop