Google and CrowdStrike dismantle botnet targeting open source developers

Cát Tiên |

Google and CrowdStrike dismantle Glassworm botnet specializing in spreading malware, stealing passwords and attacking open source developers.

US cybersecurity company CrowdStrike said it has cooperated with Google and the non-profit Shadowserver Foundation to successfully dismantle the Glassworm botnet, which is used by hackers to spread malware and steal passwords from open source software developers.

According to CrowdStrike, this campaign aims to disrupt the operation of the cybercrime group behind Glassworm, which has targeted the open source software supply chain for the past two years.

This is considered one of the serious threats to the global software development ecosystem.

Recently, many hacker groups have continuously attacked open source developers and projects to install malware on software widely used by businesses and organizations.

This form of attack is particularly dangerous because it exploits the trust of the technology community in source code storage platforms such as GitHub.

CrowdStrike believes that developers are now becoming high-value targets of hackers. Just by successfully infiltrating a programmer's computer, hackers can install malware into software or libraries used by thousands of businesses, thereby creating large-scale supply chain attacks.

To spread malware, the Glassworm group used many different methods. They posted malicious extensions on application stores for programmers, deployed malicious ads to trick users into downloading malware-infected software, and at the same time took advantage of stolen login information in previous attacks to steal developer accounts.

After controlling the account, hackers secretly inserted malware into open source software projects. CrowdStrike said that this group infected more than 300 source code stores on GitHub before being discovered.

In the crackdown campaign, CrowdStrike disabled four control and administration servers that Glassworm used to operate the botnet network. This helped cut off the connection between hackers and infected devices, preventing the risk of further malware spread.

According to CrowdStrike, Glassworm's control infrastructure is built quite sophisticatedly, based on blockchain Solana, BitTorrent peer-to-peer network, Google Calendar and virtual private servers to hide activities.

Experts warn that the trend of attacks on the software supply chain is increasing sharply. Just last week, a campaign called "Mini Shai-Hulud" attacked many open source projects with malicious updates. At least two OpenAI developers are believed to have been compromised in this incident.

Cát Tiên
RELATED NEWS

DuckDuckGo benefits when users turn their backs on Google's AI

|

DuckDuckGo recorded a sharp increase in installations in the US as many users search for search engines that do not integrate default AI like Google.

6 search engines to replace Google for users who want to avoid AI and advertising

|

6 search engines to replace Google are considered suitable for users who want to search for information in a simpler, more private and less AI-dependent way.

Google is gradually regaining its position in the AI race with Gemini

|

Google is showing a strong return in the AI race as Gemini is growing rapidly, deeply integrated into popular global services and devices.

Dog thieves brazenly steal dogs in front of homeowners and then return to threaten them

|

Lam Dong - Camera recorded the scene of 2 dog thieves riding a motorbike to steal dogs right in front of the homeowner and then turning back to threaten when chased.

People's meeting to clarify reflections on receiving 2,000 VND in storm support in Gia Lai

|

Gia Lai - Binh Dinh Ward is holding a people's meeting to clarify the reflection that people waited for many hours but only received a few thousand VND in damage support due to storm No. 13.

Northern region is about to welcome thunderstorms, ending widespread intense heat

|

Forecast for the evening and night of May 28th, the North will have scattered showers and thunderstorms; from May 29th, widespread intense heat will end.

Thai Nguyen Chairman directs inspection of ash and slag storage yard on the Cau River bank

|

After the reflection of Lao Dong Newspaper, the Chairman of Thai Nguyen Provincial People's Committee directed functional sectors to inspect the ash and slag storage yard near the Cau River bank and strictly handle violations if any.

Summoning 780 official delegates to attend the 14th Vietnam Trade Union Congress

|

The Presidium of the Vietnam General Confederation of Labour has just issued a Decision on convening delegates to attend the 14th Vietnam Trade Union Congress, term 2026-2031 (Decision).

DuckDuckGo benefits when users turn their backs on Google's AI

Cát Tiên |

DuckDuckGo recorded a sharp increase in installations in the US as many users search for search engines that do not integrate default AI like Google.

6 search engines to replace Google for users who want to avoid AI and advertising

Cát Tiên |

6 search engines to replace Google are considered suitable for users who want to search for information in a simpler, more private and less AI-dependent way.

Google is gradually regaining its position in the AI race with Gemini

Cát Tiên |

Google is showing a strong return in the AI race as Gemini is growing rapidly, deeply integrated into popular global services and devices.