Water Curse is a cybercrime threat cluster associated with large-scale abuse of GitHub as a malware distribution and attack-enablement platform. The actor is known for operating numerous weaponized repositories masquerading as penetration-testing utilities, developer tools, cheats, account checkers, and other attractive software themes in order to lure victims into executing multi-stage malware. Security reporting has tracked the cluster since at least 2023. Water Curse has been linked to campaigns involving dozens of malicious GitHub repositories and accounts. Its delivery chains commonly rely on obfuscated script-based loaders, including Visual Basic Script and PowerShell, as well as malicious Visual Studio project logic and Electron-based payload packaging. Malware attributed to the cluster has included remote-access and credential-theft functionality, including Sakura-RAT, along with components designed to steal browser data, credentials, session tokens, and other sensitive information. Reported tooling also includes modules characterized as OSINT scrapers, game cheats, cryptocurrency-related tools, and credential stealers. The actor emphasizes stealth, scalability, and layered execution. Observed tradecraft includes heavily obfuscated loaders, encrypted archives, staged payload retrieval, system reconnaissance, persistence establishment, anti-debugging, privilege escalation, defense evasion, and scripts intended to weaken host defenses and hinder recovery. In victim environments, the malware has been used for data theft and persistent remote access. Water Curse has also been associated with abuse of GitHub Actions and compromised source repositories to turn trusted development infrastructure into operational attack infrastructure. In one notable campaign, attackers inserted large numbers of malicious workflow files into compromised repositories tied to a legitimate software maintainer. Rather than relying on end-user execution, the workflows abused GitHub-hosted runners to download Linux payloads, scan for exposed cPanel and WebHost Manager systems, exploit CVE-2026-41940, and harvest credentials, configuration data, cloud and developer secrets, database access material, SSH-related data, and other sensitive information from compromised servers. This activity indicates that Water Curse is capable not only of malware distribution but also of opportunistic server-side exploitation and credential theft at scale. The cluster has shown tactical overlap with broader distribution-as-a-service style ecosystems that abuse trusted platforms and social proof to spread malware, although a direct formal linkage to a specific DaaS operation has not been conclusively established. Water Curse is best characterized as a financially motivated cybercrime actor focused on credential theft, remote access, and scalable abuse of software development platforms rather than a confirmed nation-state intrusion set. No verified sub-groups are currently established in the available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat cluster previously tracked for operating a GitHub-based ghost network that redirects users to GitHub pages hosting malware-laced payloads.
Uses weaponized GitHub repositories to deliver multi-stage malware enabling credential/session token theft, data exfiltration, remote access, and persistence.
Weaponizes GitHub repositories (posing as pentesting/red-team tools) to distribute multi-stage malware for financially motivated objectives, including credential/session token theft and long-term remote access.
Operating malicious GitHub repositories to distribute multi-stage malware that steals credentials, browser data, and session tokens while establishing persistent remote access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.