CSIDB logo
Incident

Fosshub

Incident posture

Attack window
Aug 2016
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Fosshub
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacking group known as PeggleCrew compromised a software distribution platform by exploiting an unauthenticated network service, gaining access to FTP credentials and email systems. The attackers replaced legitimate installers for applications like Audacity and Classic Shell with malicious payloads designed to hijack the Master Boot Record, causing affected systems to display a prank message upon reboot while allowing recovery. The platform's administrators subsequently took the site offline to mitigate the incident. This breach followed prior social media account takeovers attributed to the same group.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around August 1, 2016, the hacking group PeggleCrew compromised the Fosshub software distribution platform by exploiting an unauthenticated network service. This breach provided unauthorized access to Fosshub's infrastructure, including FTP credentials and Google Apps-hosted email accounts. The attackers altered legitimate software installers hosted on the site, specifically targeting downloads for Audacity and Classic Shell applications. They embedded malicious code within these installers designed to overwrite the Master Boot Record (MBR) of affected systems. When users executed the compromised installers and subsequently rebooted their devices, the malware activated and displayed a prank message. While the MBR modification disrupted normal system operation, the effects were reversible without permanent data destruction. Fosshub administrators became aware of the compromise and temporarily took the entire website offline to contain the incident and prevent further malware distribution.

The incident represented an escalation in PeggleCrew's activities, as the group had previously gained attention for hijacking high-profile Twitter accounts belonging to musician Ringo Starr and the National Football League (NFL). By targeting a software distribution platform rather than individual social media accounts, the attackers expanded their impact to potentially affect thousands of downloaders seeking legitimate open-source tools. The compromise lasted until Fosshub's administrators detected the breach and suspended service. No evidence suggested persistent data theft or espionage objectives beyond the MBR hijacking prank. The temporary website takedown disrupted Fosshub's operations but allowed remediation efforts to remove the malicious payloads and restore legitimate software offerings.

Sources

Sources available to members: 1 source.

CSIDB