Cyber Incident Victim: Fosshub
Date:
Aug 2016
Location:
United States of America
Summary
A hacking group known as PeggleCrew compromised a software distribution platform by exploiting an unauthenticated network service, gaining access to FTP credentials and email systems. The attackers replaced legitimate installers for applications like Audacity and Classic Shell with malicious payloads designed to hijack the Master Boot Record, causing affected systems to display a prank message upon reboot while allowing recovery. The platform's administrators subsequently took the site offline to mitigate the incident. This breach followed prior social media account takeovers attributed to the same group.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around August 1, 2016, the hacking group PeggleCrew compromised the Fosshub software distribution platform by exploiting an unauthenticated network service. This breach provided unauthorized access to Fosshub's infrastructure, including FTP credentials and Google Apps-hosted email accounts. The attackers altered legitimate software installers hosted on the site, specifically targeting downloads for Audacity and Classic Shell applications. They embedded malicious code within these installers designed to overwrite the Master Boot Record (MBR) of affected systems. When users executed the compromised installers and subsequently rebooted their devices, the malware activated and displayed a prank message. While the MBR modification disrupted normal system operation, the effects were reversible without permanent data destruction. Fosshub administrators became aware of the compromise and temporarily took the entire website offline to contain the incident and prevent further malware distribution.

The incident represented an escalation in PeggleCrew's activities, as the group had previously gained attention for hijacking high-profile Twitter accounts belonging to musician Ringo Starr and the National Football League (NFL). By targeting a software distribution platform rather than individual social media accounts, the attackers expanded their impact to potentially affect thousands of downloaders seeking legitimate open-source tools. The compromise lasted until Fosshub's administrators detected the breach and suspended service. No evidence suggested persistent data theft or espionage objectives beyond the MBR hijacking prank. The temporary website takedown disrupted Fosshub's operations but allowed remediation efforts to remove the malicious payloads and restore legitimate software offerings.
