Post #1262449
2026-04-17 13:28 UTC
⚠️ Heads up #infosec community
Found a malicious GitHub repo posing as a curated list of cybersecurity Telegram channels.
Every link in the README points to the same ZIP payload containing luad.exe (malware family: Alevaul). Detected by Microsoft Defender before execution.
VT 0/91 on URL but MDE flagged it as True Positive. Classic evasion.
🔗 https://github.com/simplefastfunnels254/tg-cybersec
Reported to GitHub under Active Malware / DSA Article 16.
#CyberSecurity #ThreatIntel #MDE #Malware #GitHub #OSINT
Replies (1)
-
@Bluewall@infosec.exchange 2026-04-17 13:30
Payload: luad.exe (family: Alevaul) SHA256: 88ec32a311b56441cfe6126b7780f073f36dfb8808de0dab9219d1a0be9c01ac VT: https://www.virustotal.com/gui/file/88ec32a311b56441cfe6126b7780f073f36dfb8808de0dab9219d1a0be9c01ac #MDE #Malware #IOC