A long-running espionage actor tied to Transparent Tribe is being linked to Rust-built tooling that may use private GitHub repositories as a hidden command path, a reminder that trusted developer services can become attack infrastructure.
C2Looper v2 shows how developer infrastructure can be repurposed for command-and-control without any need for custom hosting.
C2Looper is a July 2026 backdoor that researchers link, with caution, to ransomware-related activity and to a delivery path that may involve ClickFix chains.
A reported North Korea-linked campaign pairs phishing, shortcut abuse, PowerShell, and GitHub-based control with a local AI workflow that could make the next lure faster to build.
A reported Armored Likho campaign used fake donation apps, Telegram session theft, and a GitHub fallback channel to keep surveillance alive on Windows systems.