Based on monitored campaigns and accounts from mid-May to mid-June 2024, in less than a month, CPR researchers estimate that the Stargazer Goblin could have earned approximately US$8,000, and possibly more than US$100,000 since the start of operations with its 3,000 ghost accounts in 2022. Also:

  • The group operates a Distribution-as-a-Service (DaaS) network providing a platform for other potential threat actors to feed Stargazer Goblin their malicious links or malware to be distributed via malicious phishing templates on GitHub repositories. The network has been distributing all sorts of malware families, with notable mentions of Atlantida Stealer, Rhadamanthys, RisePro, Lumma Stealer, and RedLine.
  • A YouTube account linked to the group has been found to have distributed malicious links via video, suggesting a “high probability” that the Stargazer group also operates ghost accounts on social media and other platforms. This suggests a much larger DaaS universe that could spread across multiple platforms, potentially infecting and impacting a significantly greater number of users within the wider digital community.