cognitive cybersecurity intelligence

News and Analysis

Search

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.

The technique lets operators blend malicious traffic with a service that many organizations allow on their networks.

The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia.

Victims were lured with files that impersonated trusted telecom services, government updates, and software installers.

Researchers at Acronis identified HACKERAI alongside two related malware families, PATCHCORD and SHEETCORD.

The activity is assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor.

Previous reporting has also documented the group’s use of malicious files and cloud-hosted services in campaigns targeting regional government and defense interests. APT36 attacks Windows systems

Acronis said in a report shared with Cyber Security News (CSN) that the HACKERAI stands out because it does not rely on a typical attacker-controlled server for its command-and-control channel.

Afghan Telecom–themed installer metadata (Source – Acronis)

Instead, it uses GitHub Gists, a legitimate feature designed for sharing small pieces of text and code, to retrieve instructions and upload information from infected devices.

This approach can make investigations harder. Network defenders may see connections to GitHub and assume they are harmless, while the malware uses that same trusted service to maintain contact with its operators.

The campaign also shows how attackers are combining familiar delivery tricks with new communication methods.

HACKERAI Malware

The HACKERAI C2 Agent includes functions for both downloading tasks and uploading collected information through GitHub Gists.

In practical terms, an infected machine can check a Gist for instructions, carry out those instructions, and send results back through the same service.

The malware can gather basic information about a compromised system, run commands remotely, and establish persistence by altering browser shortcuts.

That shortcut abuse allows the malware to start before the legitimate browser opens, while still launching the real browser so the victim may not notice anything unusual.

Afghan Telecom TMS request portal (Source – Acronis)

Researchers also found signs that HACKERAI may have been developed with help from AI coding tools.

The sample contained AI-style comments, debugging messages, test code, a duplicated XOR routine using the same 0xAB key, and a hardcoded GitHub personal access token.

The use of legitimate cloud platforms is not new, but it remains effective because it complicates simple block-listing decisions.

A related report on the SHEETCREEP Google Sheets channel showed how threat actors can use ordinary online services to hide command traffic among normal business activity.

The HACKERAI was discovered through historical infrastructure linked to the larger operation.

Researchers found that a domain impersonating India’s Controller General of Defence Accounts had been used to distribute the framework before the newer PATCHCORD campaign emerged.

Campaign Expands Across South Asia

The wider campaign used fraudulent installers and archives to target Afghan telecom providers and Indian organizations.

One lure impersonated Afghan Telecom through a ZIP archive named TelecomTMS, while another posed as a Ministry of Defense employee breach update.

PATCHCORD, the main implant, establishes persistence by hijacking shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox.

SHEETCORD, a Go-based variant, expands this approach to Brave, Opera, and Vivaldi, while using Google Sheets rather than GitHub Gists for command traffic.

The researchers also found an exposed staging server containing phishing archives, credential theft tools, exploit code, and several command-and-control frameworks.

That discovery points to an operator preparing multiple campaigns at once, rather than relying on a single malware family or delivery route.

SuperShell login panel (Source – Acronis)

For organizations, the immediate concern is not GitHub Gists alone but suspicious behavior around them.

Security teams should investigate unexpected GitHub activity from endpoints, watch for browser shortcuts whose targets have been changed, and verify software installers received through email, messaging apps, or unfamiliar websites.

The report recommends that organizations across South Asia remain alert for sector-specific phishing attempts and monitor the listed indicators.

Staff should be especially cautious of ZIP files and installers that claim to be VPN clients, telecom tools, government updates, or urgent security software.

Similar social-engineering activity has also been seen in APT36 defense phishing campaigns. The campaign infrastructure was still active at the time of publication.

Its combination of phishing lures, shortcut hijacking, AI-assisted development patterns, and cloud-based control channels highlights a continuing shift toward tools that are easier to build and harder to separate from legitimate internet traffic.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionSHA-25674d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2HACKERAI C2 Agent executable hashFile nameAgent.exeHACKERAI C2 Agent payloadDomaindefence.cdga.siteHistorical domain impersonating India’s Controller General of Defence Accounts, associated with HACKERAI distributionDomainappstoore.solutionsPATCHCORD command-and-control domainDomainwww.appstoore.solutionsRelated PATCHCORD command-and-control domainDomainafghantelecom.siteCampaign infrastructure domain impersonating Afghan TelecomDomainafghanistanupdates.siteCampaign infrastructure domain impersonating an Afghan government updates portalDomainwww.afghanistanupdates.siteRelated campaign infrastructure domainDomaincaprispine.healthCampaign infrastructure domain impersonating a healthcare organizationDomainwww.caprispine.healthRelated campaign infrastructure domainDomainservicesindia.servicesCampaign infrastructure domainDomainwww.servicesindia.servicesRelated campaign infrastructure domainDomainzala-aer.infoCampaign infrastructure domainDomainwww.zala-aer.infoRelated campaign infrastructure domainDomainnicservice.orgCampaign infrastructure domain impersonating an Indian government serviceDomainwww.nicservice.orgRelated campaign infrastructure domainDomainnic-support.siteDomain used to serve SHEETCORDDomainappstoore.duckdns.orgHistorical dynamic DNS domain associated with the infrastructureIP address46.30.188.13Command-and-control server associated with the campaignFile nameTMSAfghanTelecom.exeMalicious installer used in the PATCHCORD delivery chainSHA-256cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6Hash for TMSAfghanTelecom.exeFile nameAFTELVPNSetup.exeAfghan Telecom VPN-themed malicious installerSHA-2561774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94Hash for AFTELVPNSetup.exeFile nameMDEBUpdateSetup.exeMinistry of Defense-themed malicious installerSHA-256378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668Hash for MDEBUpdateSetup.exeFile nameSystemHelper.vbsSHEETCORD startup persistence scriptUser-AgentBeacon1.0.0PATCHCORD HTTP user-agent string

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts