CYFIRMA Research

CYFIRMA Research- GitHub Abused to Spread Malware Disguised as Free VPN

CYFIRMA

CYFIRMA Research's latest report explores a fake "Free VPN for PC" app hosted on GitHub, delivering a packed DLL payload using obfuscated Base64 hidden in junk strings. It uses P/Invoke to load a hidden DLL, executes GetGameData, and injects into legit processes like MSBuild.exe. Packed, evasive, and anti-debug.

Link to the Research Report: https://www.cyfirma.com/research/github-abused-to-spread-malware-disguised-as-free-vpn/

#MalwareAnalysis #CyberSecurity #DLLInjection #FakeVPN      #ReverseEngineering #CYFIRMA #CYFIRMAresearch #ETLM #ExternalThreatLandscapeManagement

https://www.cyfirma.com/