HACKERAI Malware Uses GitHub Gists for Command-and-Control
Key Takeaways A new malware framework, HACKERAI C2 Agent, leverages GitHub Gists for command-and-control operations. This method allows malicious traffic to blend with legitimate network activity,...
Key Takeaways
- A new malware framework, HACKERAI C2 Agent, leverages GitHub Gists for command-and-control operations.
- This method allows malicious traffic to blend with legitimate network activity, complicating detection.
- The malware is part of a broader espionage campaign targeting critical infrastructure, government, and telecom sectors in South Asia.
- Researchers attribute the campaign with moderate confidence to APT36 (Transparent Tribe) or a closely related Pakistani threat actor.
- The campaign uses social engineering lures such as fake telecom services and government updates to deliver malware.
A recently uncovered malware framework, dubbed HACKERAI C2 Agent, is exploiting GitHub Gists to establish a covert channel for receiving attacker commands and exfiltrating sensitive data. This novel technique enables threat actors to camouflage their malicious communications within a service commonly permitted on corporate networks, making it significantly harder for security teams to detect.
Table Of Content
The discovery of HACKERAI emerged during a comprehensive investigation into an expansive cyber espionage campaign. This operation has systematically targeted critical infrastructure organizations, including telecommunications, government, defense, and energy sectors across South Asia. The attackers employed sophisticated social engineering tactics, luring victims with deceptive files masquerading as legitimate telecom utilities, official government updates, and trusted software installers.
Security researchers at Acronis identified HACKERAI as part of a cluster of related malware families, which also includes PATCHCORD and SHEETCORD. The ongoing activity is assessed with moderate confidence to overlap with the operations of APT36, also known as Transparent Tribe, or a highly affiliated threat actor with ties to Pakistan. Previous reports have extensively documented this group’s consistent use of malicious documents and cloud-hosted services in their campaigns, primarily aimed at government and defense entities within the region. APT36 typically targets Windows operating systems.
In a report shared with Cyber Security News (CSN), Acronis said in a report that HACKERAI distinguishes itself by eschewing conventional attacker-controlled servers for its command-and-control (C2) infrastructure. Instead, it utilizes GitHub Gists—a legitimate GitHub feature designed for sharing snippets of code and text—to retrieve instructions and transmit data from compromised systems. This method presents a considerable challenge for network defenders, who might perceive connections to GitHub as benign, while the malware silently leverages this trusted platform to maintain persistent communication with its operators. The campaign exemplifies a growing trend where attackers combine established delivery mechanisms with innovative communication strategies.
HACKERAI Malware Capabilities
The HACKERAI C2 Agent is engineered with dual functionalities: downloading tasks and uploading collected intelligence via GitHub Gists. This means an infected machine can query a specific Gist for operational directives, execute those instructions, and then transmit the results back through the same service.
Beyond its C2 capabilities, the malware is equipped to gather fundamental system information, execute arbitrary commands remotely, and establish persistence. A notable persistence mechanism involves altering browser shortcuts. This manipulation allows HACKERAI to launch stealthily before the legitimate browser application starts, while simultaneously opening the actual browser to avoid raising suspicion with the victim.
Researchers also uncovered indications suggesting that HACKERAI’s development may have benefited from AI coding tools. Analysis of the malware sample revealed AI-style comments, debugging messages, test code, a duplicated XOR routine employing the identical 0xAB key, and a hardcoded GitHub personal access token. The strategic use of legitimate cloud platforms, while not entirely new, remains highly effective due to the difficulty in implementing simple block-listing rules. A related report on the SHEETCREEP Google Sheets channel previously highlighted how threat actors exploit ordinary online services to mask command traffic amidst regular business activities.
HACKERAI’s detection originated from historical infrastructure linked to the broader espionage operation. Investigators discovered that a domain impersonating India’s Controller General of Defence Accounts had been instrumental in distributing the framework prior to the emergence of the more recent PATCHCORD campaign.
Campaign Expands Across South Asia
The overarching campaign has employed deceptive installers and archives to target Afghan telecom providers and various Indian organizations. One notable lure mimicked Afghan Telecom services through a ZIP archive named “TelecomTMS,” while another posed as an urgent Ministry of Defense employee breach update.
PATCHCORD, identified as the primary implant in this campaign, achieves persistence by hijacking shortcuts for popular web browsers including Microsoft Edge, Google Chrome, and Mozilla Firefox. SHEETCORD, a variant written in Go, extends this attack vector to Brave, Opera, and Vivaldi browsers, but notably utilizes Google Sheets instead of GitHub Gists for its command-and-control communications.
Further investigation led to the discovery of an exposed staging server that contained a trove of phishing archives, credential theft tools, exploit code, and multiple command-and-control frameworks. This finding strongly suggests that the operators are simultaneously preparing a multitude of campaigns, rather than relying on a singular malware family or a limited set of delivery methods.
For organizations, the primary concern extends beyond GitHub Gists themselves to any anomalous behavior associated with them. Security teams are advised to investigate unexpected GitHub activity originating from endpoint devices, meticulously monitor for altered browser shortcuts, and rigorously verify the authenticity of all software installers received via email, messaging applications, or unverified websites.
The report underscores the critical need for organizations across South Asia to maintain heightened vigilance against sector-specific phishing attempts and to actively monitor for the listed indicators of compromise. Employees should exercise extreme caution with ZIP files and installers claiming to be VPN clients, telecom tools, government updates, or urgent security software. Similar social engineering tactics have been observed in APT36’s defense-focused phishing campaigns. At the time of publication, the campaign’s infrastructure remained active. The sophisticated blend of phishing lures, shortcut hijacking, potential AI-assisted development, and cloud-based control channels highlights an ongoing strategic shift towards malware that is both easier to develop and more challenging to distinguish from legitimate network traffic.
What You Should Do
- Implement robust endpoint detection and response (EDR) solutions to monitor for suspicious processes and file modifications.
- Educate employees about phishing tactics, especially those impersonating government, telecom, or critical infrastructure entities.
- Verify the authenticity of all software installers and updates through official vendor channels only, avoiding downloads from emails or unverified websites.
- Monitor network traffic for unusual connections to legitimate services like GitHub or Google Sheets, particularly from internal endpoints.
- Regularly audit browser shortcuts for any unauthorized modifications or changes to their target paths.
- Deploy email and web filtering solutions to block known malicious domains and prevent access to phishing sites.
- Review and enhance incident response plans to address sophisticated social engineering and cloud-based C2 attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.