HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.

The technique lets operators blend malicious traffic with a service that many organizations allow on their networks.

The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia.

Victims were lured with files that impersonated trusted telecom services, government updates, and software installers.

Researchers at Acronis identified HACKERAI alongside two related malware families, PATCHCORD and SHEETCORD.

The activity is assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor.

Previous reporting has also documented the group’s use of malicious files and cloud-hosted services in campaigns targeting regional government and defense interests. APT36 attacks Windows systems

Acronis said in a report shared with Cyber Security News (CSN) that the HACKERAI stands out because it does not rely on a typical attacker-controlled server for its command-and-control channel.

Afghan Telecom–themed installer metadata (Source – Acronis)

Instead, it uses GitHub Gists, a legitimate feature designed for sharing small pieces of text and code, to retrieve instructions and upload information from infected devices.

This approach can make investigations harder. Network defenders may see connections to GitHub and assume they are harmless, while the malware uses that same trusted service to maintain contact with its operators.

The campaign also shows how attackers are combining familiar delivery tricks with new communication methods.

HACKERAI Malware

The HACKERAI C2 Agent includes functions for both downloading tasks and uploading collected information through GitHub Gists.

In practical terms, an infected machine can check a Gist for instructions, carry out those instructions, and send results back through the same service.

The malware can gather basic information about a compromised system, run commands remotely, and establish persistence by altering browser shortcuts.

That shortcut abuse allows the malware to start before the legitimate browser opens, while still launching the real browser so the victim may not notice anything unusual.

Afghan Telecom TMS request portal (Source – Acronis)

Researchers also found signs that HACKERAI may have been developed with help from AI coding tools.

The sample contained AI-style comments, debugging messages, test code, a duplicated XOR routine using the same 0xAB key, and a hardcoded GitHub personal access token.

The use of legitimate cloud platforms is not new, but it remains effective because it complicates simple block-listing decisions.

A related report on the SHEETCREEP Google Sheets channel showed how threat actors can use ordinary online services to hide command traffic among normal business activity.

The HACKERAI was discovered through historical infrastructure linked to the larger operation.

Researchers found that a domain impersonating India’s Controller General of Defence Accounts had been used to distribute the framework before the newer PATCHCORD campaign emerged.

Campaign Expands Across South Asia

The wider campaign used fraudulent installers and archives to target Afghan telecom providers and Indian organizations.

One lure impersonated Afghan Telecom through a ZIP archive named TelecomTMS, while another posed as a Ministry of Defense employee breach update.

PATCHCORD, the main implant, establishes persistence by hijacking shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox.

SHEETCORD, a Go-based variant, expands this approach to Brave, Opera, and Vivaldi, while using Google Sheets rather than GitHub Gists for command traffic.

The researchers also found an exposed staging server containing phishing archives, credential theft tools, exploit code, and several command-and-control frameworks.

That discovery points to an operator preparing multiple campaigns at once, rather than relying on a single malware family or delivery route.

SuperShell login panel (Source – Acronis)

For organizations, the immediate concern is not GitHub Gists alone but suspicious behavior around them.

Security teams should investigate unexpected GitHub activity from endpoints, watch for browser shortcuts whose targets have been changed, and verify software installers received through email, messaging apps, or unfamiliar websites.

The report recommends that organizations across South Asia remain alert for sector-specific phishing attempts and monitor the listed indicators.

Staff should be especially cautious of ZIP files and installers that claim to be VPN clients, telecom tools, government updates, or urgent security software.

Similar social-engineering activity has also been seen in APT36 defense phishing campaigns. The campaign infrastructure was still active at the time of publication.

Its combination of phishing lures, shortcut hijacking, AI-assisted development patterns, and cloud-based control channels highlights a continuing shift toward tools that are easier to build and harder to separate from legitimate internet traffic.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2 HACKERAI C2 Agent executable hash
File name Agent.exe HACKERAI C2 Agent payload
Domain defence.cdga.site Historical domain impersonating India’s Controller General of Defence Accounts, associated with HACKERAI distribution
Domain appstoore.solutions PATCHCORD command-and-control domain
Domain www.appstoore.solutions Related PATCHCORD command-and-control domain
Domain afghantelecom.site Campaign infrastructure domain impersonating Afghan Telecom
Domain afghanistanupdates.site Campaign infrastructure domain impersonating an Afghan government updates portal
Domain www.afghanistanupdates.site Related campaign infrastructure domain
Domain caprispine.health Campaign infrastructure domain impersonating a healthcare organization
Domain www.caprispine.health Related campaign infrastructure domain
Domain servicesindia.services Campaign infrastructure domain
Domain www.servicesindia.services Related campaign infrastructure domain
Domain zala-aer.info Campaign infrastructure domain
Domain www.zala-aer.info Related campaign infrastructure domain
Domain nicservice.org Campaign infrastructure domain impersonating an Indian government service
Domain www.nicservice.org Related campaign infrastructure domain
Domain nic-support.site Domain used to serve SHEETCORD
Domain appstoore.duckdns.org Historical dynamic DNS domain associated with the infrastructure
IP address 46.30.188.13 Command-and-control server associated with the campaign
File name TMSAfghanTelecom.exe Malicious installer used in the PATCHCORD delivery chain
SHA-256 cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6 Hash for TMSAfghanTelecom.exe
File name AFTELVPNSetup.exe Afghan Telecom VPN-themed malicious installer
SHA-256 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94 Hash for AFTELVPNSetup.exe
File name MDEBUpdateSetup.exe Ministry of Defense-themed malicious installer
SHA-256 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668 Hash for MDEBUpdateSetup.exe
File name SystemHelper.vbs SHEETCORD startup persistence script
User-Agent Beacon1.0.0 PATCHCORD HTTP user-agent string

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world