Skip to main content
Back to Newswire
Cybersecurity

CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks

CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks Image: Primary
CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open source software developers. The takedown disrupted the Glassworm botnet, which has targeted the open source software supply chain for two years, according to CrowdStrike. Several hacking groups have targeted developers and open source projects to push malicious software to companies and organizations. These attacks exploit the trust companies put into code hosted on platforms like GitHub. CrowdStrike said adversaries are no longer just targeting products but the developers who build them. Developers represent uniquely high value targets because compromising a single developers workstation can cascade into a supply chain compromise that impacts thousands of downstream organizations and users, the company reported. The hackers used several strategies to push out their malicious code, including publishing malicious extensions on a marketplace used CrowdStrike took down four command and control channels used It is not clear what legal or technical
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch and reviewed by the T&B editorial agent team.