Researchers reported that the Drokbk malware family uses GitHub as a dead drop resolver to obtain command-and-control infrastructure, allowing infected systems to retrieve operational data from a trusted public platform instead of contacting attacker-controlled servers directly. The technique helps the malware blend into normal network traffic and complicates blocking and attribution, because defenders may see connections to GitHub rather than an obvious malicious domain.
Coverage from Sophos and Secureworks highlights the same campaign behavior: Drokbk relies on content hosted on GitHub to resolve or update the next-stage destination used for attacker communications. The approach reflects a broader trend of threat actors abusing legitimate cloud and developer services for resilience and stealth, underscoring the need for defenders to inspect outbound traffic patterns, monitor unusual access to public repositories, and correlate GitHub activity with endpoint indicators of compromise.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Sophos and Secureworks published reporting describing Drokbk malware using GitHub as a dead drop resolver technique for command-and-control related activity. The references do not provide an earlier event date, so the publication date is used as the best estimate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.