Fake Telegram Proxy Repositories on GitHub Deliver Stealer Malware to Home Users Seeking to Bypass Restrictions
Home users searching for ways to bypass Telegram restrictions are falling victim to a new wave of malware distributed through GitHub and its mirror sites. Experts from Solar 4RAYS, part of GC Solar, have identified numerous fake repositories that appear in top positions of Russian search engine results and deliver information-stealing trojans instead of functional proxy tools.
Attackers have rapidly capitalized on increased demand for Telegram proxies. When legitimate repository links disappear from search results, malicious pages immediately occupy the freed space. Users encounter familiar names, polished descriptions, and seemingly authentic project pages, leading them to download what they believe is legitimate software.
The counterfeit repositories are crafted with considerable attention to detail. Fraudsters replicate the original README files, project layout, and even the donation information of genuine developers, making the deception difficult to detect at first glance. Once executed, the payloads—identified as Salat Stealer, Santa Stealer, and similar variants—harvest browser sessions, login credentials, and files of targeted formats.
How the Infection Works
The attack chain begins with users seeking proxy solutions to restore access to Telegram. Instead of obtaining working tools, they receive malware capable of extracting sensitive data that can be used for account hijacking and further fraud. The high level of trust placed in GitHub as a reputable hosting platform significantly increases the success rate of these campaigns.
While GitHub provides the infrastructure, the platform cannot always review the large volume of newly uploaded files in real time. This gap is actively exploited by threat actors who create convincing replicas of popular utilities.
Recommendations from Researchers
Security experts advise against downloading utilities automatically. Key red flags include:
- A brand-new author account with no history
- Absence of stars, forks, or issue reports
- Lack of commit history or bug tracking
- Explicit instructions to disable antivirus software before installation
Any of these signs should prompt users to avoid the repository entirely and seek verified sources through official channels.
Related articles
Distributed Crawler Poses as Human Visitor to Evade Analytics and Ad Filters
A detailed investigation revealed a sophisticated distributed crawler that successfully mimicked legitimate human browsing behavior across multiple unrelated websites. The crawler generated realistic events in Google Analytics while avoiding ad script loading and resource chains that would confirm genuine user sessions. Server logs showed consistent patterns of fake search engine referrers, internal navigation with fabricated Referer headers, and selective requests limited mostly to images returning 404 errors. Analysts built a graph-based detection system that correlated events across sites to expose the coordinated activity despite individual requests appearing benign. The campaign rotated browser signatures and IP addresses frequently, making single-site rate limiting ineffective. The case demonstrates how modern crawlers can exploit Measurement Protocol and incomplete bot detection to consume server resources without contributing to revenue.
Comprehensive Collection of Malware Analysis and Development Books Released for Security Researchers
A detailed roundup of professional literature covering malware development, reverse engineering, and defensive analysis has been published. The selection includes resources focused on Windows, macOS, and Android platforms. Key titles address practical techniques for building and dissecting malicious software, evasion methods, and forensic investigation. Books such as MalDev Academy and Practical Malware Analysis provide hands-on training with real-world samples and laboratory exercises. Additional volumes explore macOS-specific threats and Android malware detection using machine learning. The compilation aims to support both red team practitioners and malware analysts in deepening their technical expertise.
Bots Now Form Over Half of Global Internet Traffic in 2025, Driving API Attacks and Business Metric Distortion
Automated clients generated more than 50% of analyzed internet traffic in 2025, with malicious bots responsible for 40% of the total volume. AI-enabled automation attacks increased 12.5 times year-over-year, while daily API attacks rose 113% according to Akamai data. Simple scripts still dominate volume at 59% of bot traffic, yet sophisticated botnets exceeding 4.5 million devices now distribute activity across residential proxies and compromised endpoints. Credential stuffing, scraping, and transaction abuse continue to target business logic rather than software vulnerabilities, distorting analytics, inflating infrastructure costs, and degrading user experience. Cloudflare reports that 20% of verified bot traffic now comes from AI crawlers, blurring lines between beneficial and harmful automation. Organizations must classify bots by intent, delegation, and business impact instead of relying on IP reputation or single signals such as User-Agent strings.
Astaroth Trojan Hijacks WhatsApp Web Sessions to Spread Banking Malware to Contacts
The operators of the Astaroth banking Trojan, also known as Guildma, have added a new module that turns infected Windows systems into automated spam bots for WhatsApp Web. The malware copies browser profiles from Chrome or Edge, launches a legitimate WebDriver instance, and connects to an already authenticated WhatsApp Web session using the WPPConnect/WA-JS library. Once active, the bot scans the victim's contact list and sends each recipient a personalized greeting, a ZIP archive containing the Astaroth loader, and a closing message, all generated with randomized phrasing to evade detection. The technique leverages the trust users place in messages from known contacts, significantly increasing the likelihood of successful infection. Researchers at CrowdStrike note code similarities with tools used by other Latin American groups, including Vareg, suggesting shared development or active exchange of components. Indicators of compromise include PowerShell downloads of WebDriver, creation of ChromeAuto_ folders in C:\Users\Public\Temp, headless Chromium execution, and network activity tied to WPPConnect components.