Malware
Drokbk
Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure.
Drokbk is a Windows malware family operated by APT35.
Background
A distinctive trait of Drokbk is that it incorporates GitHub into its C&C infrastructure, which complicates detection and removal since GitHub is not typically regarded as a malicious platform.
Drokbk operations have been attributed to the Iranian APT group Nemesis Kitten, which is thought to deploy the malware for cyberespionage and theft of financial information.
Source: Malpedia (Fraunhofer FKIE).