From 60cf82992fde35c15dcaf579eb3daf2ce2271a84 Mon Sep 17 00:00:00 2001 From: CERT Orange Cyberdefense <5493049+cert-orangecyberdefense@users.noreply.github.com> Date: Thu, 13 Mar 2025 17:04:13 +0100 Subject: [PATCH] history typo --- smartloader/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/smartloader/README.md b/smartloader/README.md index f043be7..08a8348 100644 --- a/smartloader/README.md +++ b/smartloader/README.md @@ -1,7 +1,7 @@ -Following a recent TrendMicro [investigation](https://www.trendmicro.com/en_us/research/25/c/ai-assisted-fake-github-repositories.html), we have found many GitHub repositories actively delivering SmartLoader. SmartLoader is Lua-written loader distributed since early 2024. +Following a recent TrendMicro [investigation](https://www.trendmicro.com/en_us/research/25/c/ai-assisted-fake-github-repositories.html), we have found many GitHub repositories actively delivering SmartLoader. SmartLoader is Lua-written loader distributed since mid 2023. In recent campaigns, threat actors have been creating new GitHub repositories populated with an AI generated README and filled with fake backdated commits. We have also observed the same payloads being distributed via inactive repositories. These repositories are typically forked, with a new release containing SmartLoader ultimately added. We have uploaded on our [GitHub](https://github.com/cert-orangecyberdefense/cti/tree/main/smartloader) an additional list of IoCs that complements TrendMicro's report. -**Released on 2025-03-12** \ No newline at end of file +**Released on 2025-03-12**