Water Curse is a cybercrime threat cluster associated with large-scale abuse of GitHub as a malware distribution and attack-enablement platform. The actor is known for operating numerous weaponized repositories masquerading as penetration-testing utilities, developer tools, cheats, and other attractive software themes in order to infect users or abuse trusted development infrastructure. Activity attributed to Water Curse has been tracked since at least 2023. Water Curse has distributed multi-stage malware through trojanized GitHub repositories and related developer ecosystems. Reported payloads and components include Sakura-RAT, credential and browser-data stealers, session-token theft tooling, and other malware delivered through obfuscated Visual Basic Script and PowerShell loaders, encrypted archives, and Electron-based applications. The actor has also concealed malicious functionality in Visual Studio project files and build workflows. Observed post-compromise behavior includes system reconnaissance, persistence, privilege escalation, anti-debugging, defense evasion, weakening of host defenses, and data exfiltration. The group has shown a strong focus on credential and secret theft. Reported collection objectives include credentials, browser information, session tokens, cloud and developer secrets, database access material, SSH-related data, API credentials, payment-service credentials, and other sensitive configuration data. Water Curse activity has been characterized as scalable and stealth-oriented, with tooling spanning credential theft, remote access, OSINT collection, and crypto-related lures. Water Curse has also been linked through tactical overlap to campaigns that abuse GitHub-hosted automation and compromised repositories as distributed attack infrastructure. In one such operation, malicious GitHub Actions workflows were inserted into multiple development packages tied to a legitimate maintainer, causing GitHub-hosted runners to download Linux payloads, scan for exposed cPanel and WebHost Manager systems, exploit CVE-2026-41940, and harvest credentials and other secrets from compromised servers. This activity indicates that Water Curse is not limited to endpoint malware delivery, but can also operationalize software supply-chain compromise and cloud-hosted CI/CD infrastructure for opportunistic server-side credential theft. The actor has been compared with distribution-as-a-service ecosystems because of its use of numerous repositories and scalable delivery methods, although a direct formal linkage to a broader DaaS operator has not been conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat cluster previously tracked for operating a GitHub-based ghost network that redirects users to GitHub pages hosting malware-laced payloads.
Uses weaponized GitHub repositories to deliver multi-stage malware enabling credential/session token theft, data exfiltration, remote access, and persistence.
Weaponizes GitHub repositories (posing as pentesting/red-team tools) to distribute multi-stage malware for financially motivated objectives, including credential/session token theft and long-term remote access.
Operating malicious GitHub repositories to distribute multi-stage malware that steals credentials, browser data, and session tokens while establishing persistent remote access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.