Attackers Use Dormant GitHub Accounts to Map Corporate Orgs

Datadog Security Labs warns of campaigns using dormant GitHub accounts and compromised OAuth tokens to scrape corporate GitHub organizations and user data through the GitHub API. Attackers automate scraping with custom or legitimate-sounding user agents to blend in and avoid detection.

Why it matters

Understanding this tactic helps SOC teams detect and mitigate stealthy reconnaissance activity on GitHub.

SOC impact

SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.

Recommended actions

  1. Determine whether affected users, domains, or third-party providers intersect with your organization.
  2. Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
  3. Review MFA coverage and initiate credential resets where exposure is confirmed.

Executive Summary

Datadog Security Labs warns of campaigns using dormant GitHub accounts and compromised OAuth tokens to scrape corporate GitHub organizations and user data through the GitHub API. Attackers automate scraping with custom or legitimate-sounding user agents to blend in and avoid detection. Understanding this tactic helps SOC teams detect and mitigate stealthy reconnaissance activity on GitHub.

SOC Impact

SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.

Credential and Exposure Checks

  • Determine whether affected users, domains, or third-party providers intersect with your organization.
  • Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
  • Review MFA coverage and initiate credential resets where exposure is confirmed.

Why It Matters

Understanding this tactic helps SOC teams detect and mitigate stealthy reconnaissance activity on GitHub.

Source