60 Malicious Ruby Gems Used in Targeted Credential Theft Cam...
Blog post from Socket
A malware campaign in the RubyGems ecosystem has been uncovered, involving 60 malicious gems that disguise themselves as automation tools for platforms like Instagram, Twitter/X, TikTok, and others, to steal user credentials. The campaign, active since at least March 2023, was orchestrated by a threat actor using aliases such as `zon` and `nowon`, who published these gems to target primarily South Korean users, as indicated by Korean-language user interfaces and the use of `.kr` domains for exfiltration. These gems, while delivering their promised functionalities, covertly exfiltrate credentials to threat actor-controlled servers, classifying them as infostealer malware. The campaign has targeted grey-hat marketers, who rely on disposable social media accounts for spam and SEO campaigns, allowing the malware to operate undetected for over a year. The gems have been engineered to exploit this environment by embedding credential theft functionalities and leveraging infrastructure that can be used beyond commercial abuse, potentially even for disinformation or financial manipulation. Despite some gems being removed, others remain live, continuing to pose a threat by harvesting sensitive data from unsuspecting users.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.