Gitloker

MISP
Type:
Unknown
Country:
Unknown
First seen:
Unknown
Details:

Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.

Metadata
ID: 688
Created: 13/01/2026 17:48
Updated: 07/03/2026 16:00