ischhfd83 is a threat actor identifier associated with a large GitHub-based malware distribution campaign that operated primarily from 2024 to 2025 and may have begun as early as 2022. The activity centered on publishing more than one hundred backdoored repositories masquerading as remote access trojans, exploits, attack tools, video game cheats, bots, and cryptocurrency-related utilities. The campaign primarily targeted novice cybercriminals, would-be malware users, and gamers seeking cheats, using poisoned source code and fake open-source projects to compromise the downloader rather than provide the promised tool. A notable example linked to this activity is Sakura RAT, which was promoted as a sophisticated remote access trojan but was assessed to be largely nonfunctional as an offensive tool. Its code substantially reused AsyncRAT components, while key forms were left empty and a malicious Visual Basic PreBuild event silently downloaded additional malware onto the user’s system. Across the broader cluster, the same build-stage backdooring technique appeared repeatedly, indicating a scalable malware delivery operation rather than isolated repository tampering. The actor also used legitimacy-laundering tactics to make the repositories appear trustworthy. Observed methods included automated commit generation through GitHub Actions workflows, unusually large commit volumes over short periods, and networks of related contributor accounts with highly similar naming patterns and limited activity outside the associated repositories. This behavior is consistent with a distribution-as-a-service model designed to attract victims through apparently active and credible development projects. High-confidence reporting links the operation to Russian infrastructure through account attribution evidence. The actor’s demonstrated capabilities include initial access via trojanized software, credential theft through infostealer delivery, persistence and post-exploitation via installed remote access trojans, defense evasion through deceptive repository presentation, and exfiltration as a likely downstream effect of the delivered infostealers. No high-confidence evidence indicates ransomware or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a distribution-as-a-service style campaign using backdoored GitHub repositories disguised as malware, exploits, attack tools, and video game cheats to infect would-be cybercriminals and gamers. Sophos linked 141 repositories to this actor, with most containing malicious backdoors and automated commit activity to appear legitimate.
Operates a distribution-as-a-service style campaign using backdoored GitHub repositories disguised as malware, exploits, attack tools, and video game cheats to infect would-be cybercriminals and gamers. Sophos linked 141 repositories to this actor, with most containing malicious backdoors and automated commit activity to appear legitimate.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.