{
  "Event": {
    "analysis": "1",
    "date": "2026-07-22",
    "extends_uuid": "",
    "info": "[Threat Intel] Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign",
    "protected": false,
    "publish_timestamp": "1785586367",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1785586367",
    "uuid": "bae7c450-1825-4622-b1bc-7a59e560f4fe",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-original-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#201172",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Dependencies and Development Tools - T1195.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#110e53",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DNS - T1071.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3eb869",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Data Staging - T1074.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#3909cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Automated Collection - T1119\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Vulnerability Scanning - T1595.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#cfba47",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Automated Exfiltration - T1020\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7628f7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Unix Shell - T1059.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#add7fd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Services - T1584.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"37ebf9d7-5e9a-466f-a42c-6e60313db868\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bandwidth Hijacking - T1496.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"github\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862031",
        "to_ids": false,
        "type": "link",
        "uuid": "1591e3cf-a3cd-4270-8a32-fecfa214092b",
        "value": "https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862031",
        "to_ids": false,
        "type": "text",
        "uuid": "7a56f3d0-4327-4ddf-bfba-37828e31cdba",
        "value": "A large-scale campaign exploited GitHub Actions by compromising repositories to launch distributed attacks against cPanel and WHM servers. The operation began with compromised developer accounts, pushing malicious workflow files that executed on GitHub-hosted runners rather than through traditional package installation. These workflows downloaded Linux payloads from command-and-control infrastructure, scanned internet-facing systems, and exploited CVE-2026-41940 to harvest credentials including AWS keys, GitHub tokens, API credentials, database access, SSH materials, and cloud keys. The campaign affected approximately 6,100 to 16,000 workflow files across unrelated repositories, using ephemeral runners as disposable attack infrastructure. Stolen data was exfiltrated through HTTP POST requests with continuous heartbeat monitoring, enabling near-real-time visibility into exploitation operations across distributed infrastructure."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862031",
        "to_ids": false,
        "type": "text",
        "uuid": "8fe2e4d2-2502-4489-9ad7-8becde32fc36",
        "value": "Name: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign\nAuthor: AlienVault\nAdversary: \nTags: [\"supply chain\", \"github actions abuse\", \"cve-2026-41940\", \"distributed scanning\", \"cpanel exploitation\", \"repository compromise\", \"credential harvesting\", \"ci/cd attack\", \"whm vulnerability\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1195.001\", \"T1071.004\", \"T1074.001\", \"T1119\", \"T1082\", \"T1005\", \"T1190\", \"T1595.002\", \"T1020\", \"T1552.001\", \"T1041\", \"T1059.004\", \"T1584.006\", \"T1071.001\", \"T1105\"]\nIndustries: [\"Technology\", \"Hosting\"]"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784862031",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "c163af31-b9b6-4153-a060-d97af532c1a8",
        "value": "CVE-2026-41940"
      },
      {
        "category": "Network activity",
        "comment": "Payload Delivery URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579337",
        "to_ids": true,
        "type": "url",
        "uuid": "2afe6e6a-7b37-445e-b973-5b5a68dbb061",
        "value": "http://43.228.157.68:80/api/dl/amd64",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Payload Delivery URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579358",
        "to_ids": true,
        "type": "url",
        "uuid": "9a672b5b-4c3d-4a26-88a7-5b4a149cc2dd",
        "value": "http://43.228.157.68:80/api/dl/arm64",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Heartbeat and Exfiltration URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579378",
        "to_ids": true,
        "type": "url",
        "uuid": "86f3ac87-128e-4015-868e-3cf59eef5c33",
        "value": "http://43.228.157.68:80/api/github-heartbeat",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Heartbeat and Exfiltration URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579399",
        "to_ids": true,
        "type": "url",
        "uuid": "f94d16ea-9d30-412d-a138-2f38e25ad345",
        "value": "http://43.228.157.68:80/api/github-results",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Fourteen recovered workflows also queried a unique DNSHook hostname",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579421",
        "to_ids": true,
        "type": "hostname",
        "uuid": "f8162652-45af-4b39-9f55-c50f52abeb02",
        "value": "f5b0b742-240a-4811-8a5b-b0ba6060685d.dnshook.site",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "threat actor-controlled command and control (C2) server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579442",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "3643c573-5388-4fd7-970b-7117112a0c12",
        "value": "43.228.157.68",
        "Tag": [
          {
            "colour": "#2e63e1",
            "local": false,
            "name": "asn:asn=\"55154\"",
            "relationship_type": ""
          },
          {
            "colour": "#76a69c",
            "local": false,
            "name": "asn:as-owner=\"MADGEN-01\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "threat actor-controlled infrastructure",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579463",
        "to_ids": true,
        "type": "url",
        "uuid": "808e3059-9e7f-4029-816a-256d610ce64a",
        "value": "http://43.228.157.68/api/dl/$_s",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "\"...s the payload as an internet scanner: PANEL_URL=\"http://43[.]228[.]157[.]68:80\" \\ GOMEMLIMIT=2147483648 \\ /tmp/.svc ipscan \\ -...\"",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579484",
        "to_ids": true,
        "type": "url",
        "uuid": "70ba7a48-9cf3-4f1e-81ed-5dc797aa61c1",
        "value": "http://43.228.157.68:80",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Packagist profile",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579505",
        "to_ids": true,
        "type": "url",
        "uuid": "274b3358-2faf-42e4-bf08-fee0462f6d61",
        "value": "https://packagist.org/users/dinushchathurya/",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "GitHub profile",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579527",
        "to_ids": true,
        "type": "url",
        "uuid": "31cf1f44-60b6-45d7-82a3-b32156d491f3",
        "value": "https://github.com/dinushchathurya/",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Payload Delivery URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579547",
        "to_ids": true,
        "type": "url",
        "uuid": "391115c5-b70a-4bc8-86c7-1eafd2ccd153",
        "value": "http://43.228.157.68:80/api/dl/386",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Payload Delivery URL",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785579568",
        "to_ids": true,
        "type": "url",
        "uuid": "0a8a36bc-03de-426d-8004-582c743a6454",
        "value": "http://43.228.157.68:80/api/dl/arm",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-06-13T23:43:44+00:00",
        "last_seen": "2026-06-13T23:43:44+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1785579589",
        "uuid": "81f6ddc0-1263-4f67-bf5a-fa965aba041a",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "md5",
            "timestamp": "1785579589",
            "to_ids": true,
            "type": "md5",
            "uuid": "5ed45837-769e-4757-a7d8-645a8c02a72f",
            "value": "572745566ec674c6eae10c179b0de2ba",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "sha1",
            "timestamp": "1785578910",
            "to_ids": true,
            "type": "sha1",
            "uuid": "e6aa8740-1fe8-40b3-8ea0-949a7d13b127",
            "value": "e219da0599dea936ee867792e2dfe6a2c2a7c68b",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "sha256",
            "timestamp": "1785578910",
            "to_ids": true,
            "type": "sha256",
            "uuid": "ab2cbc14-780d-4d04-ae0f-7f714222266b",
            "value": "22f721fd3a81d2e27cbf90a122bb977f630c50b79daa98350f0e57b04dfa81f1",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 01/08/2026\nLast-scan: 29/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "text",
            "timestamp": "1785577708",
            "to_ids": false,
            "type": "text",
            "uuid": "c1a9a1ac-ff38-437e-a482-ae9e8e67268c",
            "value": "Type Description: ELF\nMicrosoft: Trojan:Linux/cPanWHM.DA!MTB\nClamAV: None\nVT Total Detection: 23/74\nFirst Submission: 2026-06-13T23:43:44+00:00\nLast Submission: 2026-06-13T23:43:44+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1785577708",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "7eda8da4-a9a0-46bc-bba3-c84437880ee4",
            "value": "98304:odIXD5W99Jo/TJsgQLBNUo0Oepl8ZBmBCEz:o25kJKTJZy5vkcmBPz"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1785577708",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "2fcbc4fa-4ea7-45df-9c75-c497f0016c03",
            "value": "10563768"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "vhash",
            "timestamp": "1785577708",
            "to_ids": true,
            "type": "vhash",
            "uuid": "0ce052cb-6286-456b-89a6-e3807f07c0ea",
            "value": "e840a106aec60742c59f25fa4dd95c2b"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-06-13T23:43:44+00:00",
            "last_seen": "2026-06-13T23:43:44+00:00",
            "object_relation": "filename",
            "timestamp": "1785577708",
            "to_ids": true,
            "type": "filename",
            "uuid": "fa7bc09d-5414-4019-abe2-c6e137d71102",
            "value": "gmesyxv6p.exe"
          }
        ]
      }
    ]
  }
}