Sawfish
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Sawfish is a threat actor also known by the alias Sawfish, with open‑source reporting indicating a possible Russian origin. The actor first came to public attention in early 2020 when GitHub’s Security Incident Response Team warned customers of an ongoing phishing campaign bearing that name. Sawfish’s activity centers on stealing GitHub credentials through deceptive web pages that mimic the legitimate login interface. By harvesting usernames and passwords, the actor gains unauthorized access to developer accounts and the code repositories they control. The group’s infrastructure is described as using phishing landing pages hosted on domains that resemble github.com.
Targets of Sawfish are primarily individuals and organizations that use GitHub for source‑code management, which includes software developers, technology firms, and any entity hosting private repositories on the platform. The actor’s observed objective is to obtain valid credentials in order to download the contents of private repositories and to establish persistent access via personal access tokens or authorized OAuth applications. No specific malware families are mentioned in the reporting; the initial access vector relies exclusively on spearphishing emails that direct victims to fraudulent login pages. Once credentials are obtained, Sawfish abuses the stolen tokens to clone or exfiltrate code, a technique that does not require traditional malware deployment. This focus on credential harvesting and token abuse defines the actor’s tooling style as lightweight and web‑based.
The most cited incident involving Sawfish occurred in April 2020 when an employee of the code‑analysis startup DeepSource fell for the phishing lure, leading to the theft of GitHub app credentials and subsequent access to private repositories. GitHub’s security team notified DeepSource of the compromise, prompting the company to rotate all user tokens, client secrets, private keys and employee credentials with production access. The event resulted in a public disclosure by DeepSource, a forced password reset for all users, and the announcement of a bug‑bounty program to improve security. While open sources list the actor’s possible location as Russia, no public attribution ties Sawfish to a specific state sponsor or criminal consortium. The DeepSource case remains the representative example of Sawfish’s capability to conduct credential‑theft campaigns against developer‑focused services.
Incidents
Attributed incidents are available to members.
1 incident