Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Malware infection exposes hackers’ RATs, phishing kits, and attack infrastructure
August 31, 2026
New Infostealer Malware Hijacks Claude Accounts, Steals Login Sessions
August 31, 2026
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
August 31, 2026
Home/Threats/Malware infection exposes hackers’ RATs, phishing kits, and attack infrastructure
Threats

Malware infection exposes hackers’ RATs, phishing kits, and attack infrastructure

Key Takeaways A self-inflicted malware infection on an attacker’s workstation revealed the full operational toolkit and infrastructure of a threat actor linked to the Blind Eagle campaign. The...

Sarah simpson
Sarah simpson
August 31, 2026 3 Min Read
2 0

Key Takeaways

  • A self-inflicted malware infection on an attacker’s workstation revealed the full operational toolkit and infrastructure of a threat actor linked to the Blind Eagle campaign.
  • The exposed resources include multiple Remote Access Trojans (AsyncRAT, DcRat, Remcos, XWorm), phishing kits, email delivery tools, and various file-hosting services.
  • The attackers employed sophisticated phishing tactics, using password-protected archives and impersonating Colombian judicial and traffic authorities to evade detection.
  • This incident provides a rare glimpse into the meticulous workflow of a cybercriminal operation, demonstrating their adaptable use of diverse malware families and legitimate services for malicious purposes.
  • Defenders should prioritize flagging password-protected archives in emails, inspecting actual file signatures, and monitoring for unusual activity involving legitimate Windows utilities and raw content services.

A recent cybersecurity investigation has inadvertently uncovered the extensive arsenal and operational infrastructure of a threat actor believed to be associated with the notorious Blind Eagle campaign. This campaign has primarily targeted organizations and individuals within Colombia and the broader Latin American region.

The significant breakthrough occurred when a separate, unrelated information-stealing malware successfully compromised what appears to be a workstation belonging to one of the attackers. This compromise inadvertently logged and exposed a wealth of data detailing the attacker’s activities, tools, and methodologies. A comprehensive report on these findings is available here.

The attackers leveraged phishing emails that meticulously mimicked official communications from Colombian judicial bodies and traffic authorities. These deceptive emails directed victims to download password-protected archives, a tactic increasingly observed in recent attacks. This method effectively bypasses automated email scanning and delays detection, granting threat actors a critical advantage.

According to a report from LevelBlue said in a report shared with Cyber Security News (CSN), analysts successfully traced a GitHub commit email address to a stolen-data log. The recovered data provided an unprecedented look into the attacker’s operational environment, including browser history, local folder structures, and credentials associated with the campaign’s logistical footprint.

While these findings do not definitively identify the individual behind the attacks, they offer a clear mapping of the entire workflow. This includes the creation of phishing content, the deployment of remote-access malware, the utilization of email delivery tools, and the reliance on various file-hosting services. The detailed exposure illustrates how these disparate elements converge to form a repeatable and scalable attack system.

Hackers’ Own Malware Infection

The investigation commenced with the GitHub account “cabeto850128,” which was observed staging components of a malware loader. This account strategically separated a legitimate AutoIt interpreter from its malicious script logic. Crucially, the commit metadata associated with this GitHub activity revealed an email address, providing a pivotal starting point for researchers without requiring a direct breach of the attacker’s account or complex malware reverse-engineering. Further details can be found in the report.

This same email address was subsequently discovered in the ALIEN TXTBASE stealer-log collection, independently linking it to an infostealer-compromised computer named “Ghost.” Stealer logs are invaluable, as they capture saved browser data and local files, offering an unparalleled view into the tools and methods threat actors typically keep hidden. The detailed log provided a rare look at the attacker’s operational environment.

Within a folder labeled “Rats” on the compromised machine, researchers found builds and artifacts related to several prominent remote-access tools (RATs), including AsyncRAT, DcRat, Remcos, and XWorm. This discovery indicates that the operator possesses the flexibility to switch payloads, rather than relying on a single malware family or delivery mechanism. The full analysis is available <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/72fdd7f8-8408-4969-925d-823a8c250c3e/Hackers-Own-Malware-Infection-Exposes-Their-RATs-Phishing-Kits-and-Attack-Infrastructure.pdf?AWSAccessKeyId=ASIA2F3EMEYEWPMZ2XI4&Signature=jRRbjkLQbPX5tWeMbwW4L7LPrD4%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD%2FWYJD69w3lgNUfgaJ7%2BwUC3jj5arFzu2r5mtjdJUhFgIhAIeARFgP4JGo6pe9qxYLbZMHnNeX%2BG9IhUgxS7ELy%2BzoKvwECI3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1Igws8Ye2PrWH0F9rCF8q0ASZaOMMJVxjys29Mpnsn1tvvrk58BvbmHmp0iFNp2rutShCqY7v%2B0S4D2OSPR5wstFnqPak6RnL7Y6bEaR0kk6m4nfbTlKRHNTiAvNTHrZ3VFoNCs6N%2B0yygV7NtYo9DI1jb9hZM86Oyz5FfwPkxCk93%2BAhzPT8mTY9YPLM0P559de%2BIT8MhdjBa5BCReZYa0bIv9Fbd2FE%2BR0vOLAf0Rvt4wwFRhXDrc4C6RZzCmx9MAIHPzzqYE7XkzmoUTyakOKt0eNmjIwWfdnghzSOv7QkHoKJbg5bt0S8qNs2Ww4U2qGCgTejFVynG7bKSHBn%2Fqi7QtvKZ9sWY2F3bbljnWSQLZ8X%2FgoCABibfVBrJvyA5blC753q4C4hfqesPJ%2BHK0zCXgpjiCTlVo9HTkO8Yc%2F7qoOTfTLy39%2BMybpfRXX0EBujlG5CwHxNQARQSPTo4avKbyFOH7C%2FcPe4HKSk59W8BF4%2BTQYZBOpsu1ta%2BKegZD39qcHPV1JITjaDAK4BtRnsw4hMtA89DOO9dK3i7MmHb%2FrittALCtG9bCEeOVy5AXTfU6lcpx2TLTNP%2BKdsX3AMJhbU9GLHsYUTd4Jr79NEk%2FLotJbJao1vGck2IemBxLRtqY6xBrWZf1wyQtLDWvmcPK2AMjQktuGA23dW%2FgFcfVKBgK

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwarePatchphishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

New Infostealer Malware Hijacks Claude Accounts, Steals Login Sessions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical ServiceNow Flaws Allow Remote Code Execution, Data Access
August 29, 2026
Critical Hugging Face Vulnerability Allowed AI Agent Hacking
August 29, 2026
Critical RCE, Prompt Injection in AI Infrastructure Expose API Keys
August 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us