Malicious Fork of Legitimate Triton App Discovered on GitHub, Exposing New Malware Threat
An unauthorized fork of the legitimate Triton macOS client for omg.lol has been identified as a vector for distributing Windows malware hosted on GitHub. The campaign exploits GitHub’s forking model and misleading README content to deceive users into…
An unauthorized fork of the legitimate Triton macOS client for omg.lol has been identified as a vector for distributing Windows malware hosted on GitHub. The campaign exploits GitHub’s forking model and misleading README content to deceive users into downloading a compromised archive, Software_3.1.zip.
The forked project, under the account "JaoAureliano," removes original attributions and rebrands itself as the official app, embedding a ZIP payload. Key sections in the README, including the download button, redirect users to a GitHub URL serving the malicious archive.
The Triton client, originally developed by Otávio C., aggregates services like Statuslog and PURLs. However, the malicious repository encourages downloading a ZIP file that conceals a Windows-focused malware under the guise of a Triton release.
Account Manipulation and Campaign Indicators
The account "JaoAureliano" hosts minimal activity, suggesting a targeted operation. The contribution graph shows backdated commits, creating an illusion of development activity. Repository topics include terms like "malware" and "pytorch," which may mislead users into perceiving it as research-oriented.
An unauthorized fork of the legitimate Triton macOS client for omg.lol has been identified as a vector for distributing Windows malware hosted on GitHub.
The payload in Software_3.1.zip, identified by SHA-256 hash 39b29c38c03868854fb972e7b18f22c2c76520cfb6edf46ba5a5618f74943eac, was detected by 12 out of 66 engines on VirusTotal.
Execution and Anti-analysis Techniques
The execution begins with 7za.exe extracting the archive, followed by a batch script (Launcher.cmd) leading to further components like luajit.exe. The malware employs anti-analysis measures such as debugger detection and virtualization checks, aligning with MITRE ATT&CK tactics.
Network activity indicates communication with endpoints such as nexusrules.officeapps.live.com and polygon-rpc.com, blending with legitimate traffic. This incident highlights the risk of open-source projects being used for malware distribution through hostile forks.
Security teams should verify repository owners, inspect commit histories, and prioritize official releases. Monitoring for the specified hash, URLs, and processes like 7za.exe and Launcher.cmd can serve as indicators of compromise.
SHA-256: 39b29c38c03868854fb972e7b18f22c2c76520cfb6edf46ba5a5618f74943eac File Size: 1.33 MB File Type: ZIP archive containing PE executables
Based on reporting by GBHackers.
