AntiMalware•July 13, 2026•🇷🇺Translated from Russian

Fake Telegram Proxy Repositories on GitHub Deliver Stealer Malware to Home Users Seeking to Bypass Restrictions

Home users searching for ways to bypass Telegram restrictions are falling victim to a new wave of malware distributed through GitHub and its mirror sites. Experts from Solar 4RAYS, part of GC Solar, have identified numerous fake repositories that appear in top positions of Russian search engine results and deliver information-stealing trojans instead of functional proxy tools.

Attackers have rapidly capitalized on increased demand for Telegram proxies. When legitimate repository links disappear from search results, malicious pages immediately occupy the freed space. Users encounter familiar names, polished descriptions, and seemingly authentic project pages, leading them to download what they believe is legitimate software.

The counterfeit repositories are crafted with considerable attention to detail. Fraudsters replicate the original README files, project layout, and even the donation information of genuine developers, making the deception difficult to detect at first glance. Once executed, the payloads—identified as Salat Stealer, Santa Stealer, and similar variants—harvest browser sessions, login credentials, and files of targeted formats.

How the Infection Works

The attack chain begins with users seeking proxy solutions to restore access to Telegram. Instead of obtaining working tools, they receive malware capable of extracting sensitive data that can be used for account hijacking and further fraud. The high level of trust placed in GitHub as a reputable hosting platform significantly increases the success rate of these campaigns.

While GitHub provides the infrastructure, the platform cannot always review the large volume of newly uploaded files in real time. This gap is actively exploited by threat actors who create convincing replicas of popular utilities.

Recommendations from Researchers

Security experts advise against downloading utilities automatically. Key red flags include:

  • A brand-new author account with no history
  • Absence of stars, forks, or issue reports
  • Lack of commit history or bug tracking
  • Explicit instructions to disable antivirus software before installation

Any of these signs should prompt users to avoid the repository entirely and seek verified sources through official channels.

Related articles

AntiMalware•Malware & Botnets

SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points

Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.

AntiMalware•Malware & Botnets

RATHat Trojan Leverages Google Gemini to Infect and Control Android Devices

The banking trojan RATHat has begun using Google Gemini as an assistant to infect Android smartphones and maintain persistence. Researchers at Cleafy report that the malware first disguises itself as a legitimate application and tricks users into granting Accessibility permissions. Once inside, RATHat activates wireless debugging, connects via ADB, and deploys a separate Go-based service running with system-level privileges. Gemini helps the trojan interpret unfamiliar Android interfaces across different versions, languages, and manufacturer skins by analyzing UI structures and suggesting the correct taps. On the attacker side, the same model processes intercepted SMS messages, evaluates bank balances, and ranks compromised devices by financial value. Since April, Cleafy has observed nearly 100 deployments of the command-and-control infrastructure, pointing to a possible malware-as-a-service model. Removing the original APK is insufficient because the Go service survives independently until reboot and can reinstall the dropped payload.

AntiMalware•Malware & Botnets

Mimbrob Malware Uses Fake Dronner App to Target Russian Military and Industrial Firms

Researchers at F6 have identified a new malware campaign dubbed Mimbrob that leverages a fake drone-tracking application called Dronner. The lure promises data on heavy Baba Yaga drones and remote mining locations but instead deploys malicious payloads aimed primarily at Russian military personnel near the front line. The malware checks system language, keyboard layouts, and interface preferences, remaining dormant or terminating if Russian or certain CIS and Romanian languages are absent. Since April 2026 the same operators have conducted phishing campaigns against Russian industrial and IT companies using FBULoader disguised as a Yandex Browser update and the RAT-Go remote access trojan. The attackers register lookalike domains of legitimate Russian enterprises to deliver fake metrology notices and court documents. While espionage appears the most probable objective, researchers have not yet obtained the final payload and therefore refrain from definitive attribution.

BoletimSec•Malware & Botnets

Group-IB Discovers RemControl Android Banking Trojan Using Dynamic Overlay Attacks to Steal Banking PINs

Group-IB has identified a new Android banking trojan named RemControl with samples dating back to July 2026. The malware targets more than 30 financial institutions across Europe, the Middle East, and Canada, with Italy and France as primary focus areas. RemControl employs an overlay technique that displays a full-screen phishing replica of the legitimate banking app when the victim launches the real application, capturing PINs, access codes, and card details before seamlessly returning control to the authentic app. Phishing screens are not bundled in the APK but are fetched dynamically from operator-controlled servers reachable via Telegram channels, allowing rapid target changes without reinfection. Distribution relies on fake Google Play listing pages that mimic a streaming application, with geo-targeted delivery for Italian visitors. The trojan requests VPN permissions to block Play Store traffic and bypass real-time security checks, followed by accessibility service access that enables screen reading, keystroke logging, remote taps, and unlock pattern reconstruction.