Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

Fraudulent

A hacker in a Guy Fawkes mask using an Apple MacBook.
Gaming Gear

Fraudulent GitHub Pages impersonate trusted companies to trick Mac users into installing malware, leaving financial and personal data at risk

by admin September 24, 2025



  • Atomic Stealer malware installs silently via fake GitHub Pages targeting Mac users
  • Attackers create multiple GitHub accounts to bypass platform takedowns repeatedly
  • Users copying commands from unverified websites risk serious system compromise

Cybersecurity researchers are warning Apple Mac users about a campaign using fraudulent GitHub repositories to spread malware and infostealers.

Research from LastPass Threat Intelligence, Mitigation, and Escalation (TIME) analysts found attackers are impersonating well-known companies to convince people to download fake Mac software.

Two fraudulent GitHub pages pretending to offer LastPass for Mac were first spotted on September 16 2025 under the username “modhopmduck476.”


You may like

How the attack chain works

While these particular pages have been taken down, the incident suggests a broader pattern that continues to evolve.

The fake GitHub pages included links labeled “Install LastPass on MacBook,” which redirected to hxxps://ahoastock825[.]github[.]io/.github/lastpass.

From there, users were sent to macprograms-pro[.]com/mac-git-2-download.html and told to paste a command into their Mac’s terminal.

That command used a CURL request to fetch a base64-encoded URL that decoded to bonoud[.]com/get3/install.sh.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The script then delivered an “Update” payload that installed Atomic Stealer (AMOS malware) into the Temp directory.

Atomic Stealer, which has been active since April 2023, is a known infostealer used by financially motivated cybercrime groups.

Investigators have linked this campaign to many other fake repositories impersonating companies ranging from financial institutions to productivity apps.


You may like

The list of targeted names includes 1Password, Robinhood, Citibank, Docker, Shopify, Basecamp, and numerous others.

Attackers appear to create multiple GitHub usernames to bypass takedowns, using Search Engine Optimization to push their malicious links higher on search results in Google and Bing.

This technique increases the chances that Mac users searching for legitimate downloads will encounter the fraudulent pages first.

LastPass states it is “actively monitoring this campaign” while working on takedowns and sharing indicators of compromise to help others detect threats.

The attackers’ use of GitHub Pages reveals both the convenience and the risks of community platforms.

Fraudulent repositories can be set up quickly, and while GitHub can remove them, attackers often return under new aliases.

This cycle raises questions about how effectively such platforms can protect users.

How to stay safe

  • Only download software from verified sources to avoid malware and ransomware risks.
  • Avoid copying commands from unfamiliar websites to prevent unauthorized code execution.
  • Keep macOS and all installed software up to date to reduce vulnerabilities.
  • Use the best antivirus or security software that includes ransomware protection to block threats.
  • Enable regular system backups to recover files if ransomware or malware strikes.
  • Stay skeptical of unexpected links, emails, and pop-ups to minimize exposure.
  • Monitor official advisories from trusted vendors for timely security updates and guidance.
  • Configure strong, unique passwords and enable two-factor authentication for important accounts.

You might also like



Source link

September 24, 2025 0 comments
0 FacebookTwitterPinterestEmail
Epic finally revokes fraudulent V-Buck purchases on Xbox, but a "malfunctioning" refund system only causes more confusion
Game Reviews

Epic finally revokes fraudulent V-Buck purchases on Xbox, but a “malfunctioning” refund system only causes more confusion

by admin September 7, 2025


Epic Games has sped up repercussions for Fortnite players who used V-Bucks and refunded them through an exploit on Xbox, essentially getting the in-game currency for free.

As we moved into the weekend, the studio said it had now “fixed a delay” and would be claiming back any items that were bought through currency that had been refunded on Xbox or previously gifted from fraudulent accounts.

Acknowledging the system it uses to revoke items on Xbox between December 2024 and July 2025 “malfunctioned”, the company warned some players “may now see a message that their payment was reversed or refunded and see recent items have been removed, even from transactions from several months ago”.

Thank You, Drive Through. Beavis and Butt-Head Are in the Shop!Watch on YouTube

It comes after some Xbox players abused an exploit through which they could buy V-Bucks through Microsoft, apply them to their accounts, and then refund them.

After clarifying this “does not affect regular purchases on Xbox or any other platform that weren’t refunded”, the Fortnite Status X/Twitter account added:

Update on Xbox refund issue:

Ordinarily, when a player receives a refund of a real-money Fortnite purchase, the purchased items are removed from their account. When V-Bucks are purchased, spent, and refunded, causing the player’s V-Bucks balance to go negative, items most…

— Fortnite Status (@FortniteStatus) September 6, 2025

To see this content please enable targeting cookies.

Manage cookie settings

“Ordinarily, when a player receives a refund of a real-money Fortnite purchase, the purchased items are removed from their account,” Epic explained. “When V-Bucks are purchased, spent, and refunded, causing the player’s V-Bucks balance to go negative, items most recently purchased and gifted with the refunded V-Bucks are removed from the player’s account and the gift recipient’s account.

“Unfortunately, the system we built for this malfunctioned on Xbox between December 2024 and July 2025. During this time, players were receiving refunds, but the refunded V-Bucks and items purchased with refunded V-Bucks remained in the player’s account and gift recipient accounts.”

While Epic accepts that over this period most players “continued using purchasing and refunding in good faith as usual”, some “exploited the situation to make large numbers of purchases, often with many accounts. Some even set up shops to accept payments from players and gifted them items purchased with refunded V-Bucks”.

It’s taken so long to sort the issue, however, that when Epic began processing back-dated refund requests on Xbox on 4th September and confusing players, it’s now “making a correction to distinguish between accounts that made ordinary refund requests, and accounts exploiting the refund system”.

“We’re restoring the items that were removed earlier this week for players who made less than 7 refunds since Dec 2024. It was our fault that we didn’t update the V-Bucks balance in their account immediately as we should have. This will take a few days,” Epic conceded.

“The removed items will stay removed for anyone who received 7 or more refunds, and for items received through gifting from players who made 7 or more refunds during this time. This is the ordinary approach to refunds from our terms of service, and these item purchases were taking advantage of an exploit with the V-Bucks refund system.”

Epic Games recently claimed the return of Fortnite to iOS in the UK is “uncertain” as it’s been unable to bring the Epic Games Store to iOS this year, “if ever”, after the CMA – the UK’s competition regulator – has “deprioritised store competition entirely”, following the lengthy legal battle between Epic and Apple.





Source link

September 7, 2025 0 comments
0 FacebookTwitterPinterestEmail
Reddit Erupts After Epic Games Belatedly Claws Back "Fraudulent" Fortnite Purchases
Game Updates

Reddit Erupts After Epic Games Belatedly Claws Back “Fraudulent” Fortnite Purchases

by admin September 5, 2025



The Fortnite Battle Royale subreddit caught fire Thursday night as many people reported that they were greeted with a pretty upsetting prompt when they logged into Fortnite, with the game telling them they’d had cosmetic items and/or V-Bucks revoked from their accounts. It was an unusual situation because it happened to so many different people at once, and in some cases removed items that the player had for months. When Epic Games finally commented about the situation on Friday morning, it said the revocations were correct and that there was a bug on Xbox specifically that prevented them from making this fix before now.

We’ve fixed a delay where items that were refunded on Xbox or previously gifted from fraudulent accounts were not immediately removed.
As a result, some players may now see a message that their payment was reversed or refunded and see recent items have been removed, even from…

— Fortnite Status (@FortniteStatus) September 5, 2025

The situation sparked dozens of Reddit threads on Thursday night and Friday morning before Epic publicly acknowledged what was going on. There are still others in these threads and in the replies to that tweet claiming innocence, or that they lost items and currency that they purchased legitimately on other platforms like PlayStation or PC. So it’s possible that this enforcement sweep has caught more players than it should have.

There are a few different scenarios in which Epic will claw back purchased items or V-Bucks, the most obvious being when a person buys V-Bucks and then refunds the purchase either through their credit card company or the platform holder–items they may have bought with those V-Bucks should be removed when the money is charged back, along with the V-Bucks themselves. Apparently, a bug caused some players to keep those V-Bucks even after they refunded them, and that’s one thing Epic is correcting now.

Other things that folks have reported doing to earn Epic’s ire include buying an account loaded with V-Bucks in order to gift items to their main account, changing their Xbox region to take advantage of lower prices in other parts of the world, and buying V-Bucks cards from grey market sellers. With Epic seemingly taking enforcement action against a lot of different people at once over months of infractions, there are many different explanations involved.

Fortnite’s FOMO-based item shop makes this situation even more awkward, because it may not possible for someone who lost some cosmetics to simply re-purchase them legitimately, since most items only appear in the shop for a few weeks per year.





Source link

September 5, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (1,098)
  • Esports (800)
  • Game Reviews (772)
  • Game Updates (906)
  • GameFi Guides (1,058)
  • Gaming Gear (960)
  • NFT Gaming (1,079)
  • Product Reviews (960)

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?
  • How to Unblock OpenAI’s Sora 2 If You’re Outside the US and Canada
  • Final Fantasy 7 Remake and Rebirth finally available as physical double pack on PS5
  • The 10 Most Valuable Cards

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal

    October 10, 2025
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?

    October 10, 2025
  • How to Unblock OpenAI’s Sora 2 If You’re Outside the US and Canada

    October 10, 2025
  • Final Fantasy 7 Remake and Rebirth finally available as physical double pack on PS5

    October 10, 2025
  • The 10 Most Valuable Cards

    October 10, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal

    October 10, 2025
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?

    October 10, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close