A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.
The technique lets operators blend malicious traffic with a service that many organizations allow on their networks.
The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia.
Victims were lured with files that impersonated trusted telecom services, government updates, and software installers.
Researchers at Acronis identified HACKERAI alongside two related malware families, PATCHCORD and SHEETCORD.
The activity is assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor.
Previous reporting has also documented the group’s use of malicious files and cloud-hosted services in campaigns targeting regional government and defense interests. APT36 attacks Windows systems
Acronis said in a report shared with Cyber Security News (CSN) that the HACKERAI stands out because it does not rely on a typical attacker-controlled server for its command-and-control channel.
Instead, it uses GitHub Gists, a legitimate feature designed for sharing small pieces of text and code, to retrieve instructions and upload information from infected devices.
This approach can make investigations harder. Network defenders may see connections to GitHub and assume they are harmless, while the malware uses that same trusted service to maintain contact with its operators.
The campaign also shows how attackers are combining familiar delivery tricks with new communication methods.
The HACKERAI C2 Agent includes functions for both downloading tasks and uploading collected information through GitHub Gists.
In practical terms, an infected machine can check a Gist for instructions, carry out those instructions, and send results back through the same service.
The malware can gather basic information about a compromised system, run commands remotely, and establish persistence by altering browser shortcuts.
That shortcut abuse allows the malware to start before the legitimate browser opens, while still launching the real browser so the victim may not notice anything unusual.
Researchers also found signs that HACKERAI may have been developed with help from AI coding tools.
The sample contained AI-style comments, debugging messages, test code, a duplicated XOR routine using the same 0xAB key, and a hardcoded GitHub personal access token.
The use of legitimate cloud platforms is not new, but it remains effective because it complicates simple block-listing decisions.
A related report on the SHEETCREEP Google Sheets channel showed how threat actors can use ordinary online services to hide command traffic among normal business activity.
The HACKERAI was discovered through historical infrastructure linked to the larger operation.
Researchers found that a domain impersonating India’s Controller General of Defence Accounts had been used to distribute the framework before the newer PATCHCORD campaign emerged.
The wider campaign used fraudulent installers and archives to target Afghan telecom providers and Indian organizations.
One lure impersonated Afghan Telecom through a ZIP archive named TelecomTMS, while another posed as a Ministry of Defense employee breach update.
PATCHCORD, the main implant, establishes persistence by hijacking shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox.
SHEETCORD, a Go-based variant, expands this approach to Brave, Opera, and Vivaldi, while using Google Sheets rather than GitHub Gists for command traffic.
The researchers also found an exposed staging server containing phishing archives, credential theft tools, exploit code, and several command-and-control frameworks.
That discovery points to an operator preparing multiple campaigns at once, rather than relying on a single malware family or delivery route.
For organizations, the immediate concern is not GitHub Gists alone but suspicious behavior around them.
Security teams should investigate unexpected GitHub activity from endpoints, watch for browser shortcuts whose targets have been changed, and verify software installers received through email, messaging apps, or unfamiliar websites.
The report recommends that organizations across South Asia remain alert for sector-specific phishing attempts and monitor the listed indicators.
Staff should be especially cautious of ZIP files and installers that claim to be VPN clients, telecom tools, government updates, or urgent security software.
Similar social-engineering activity has also been seen in APT36 defense phishing campaigns. The campaign infrastructure was still active at the time of publication.
Its combination of phishing lures, shortcut hijacking, AI-assisted development patterns, and cloud-based control channels highlights a continuing shift toward tools that are easier to build and harder to separate from legitimate internet traffic.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2 | HACKERAI C2 Agent executable hash |
| File name | Agent.exe | HACKERAI C2 Agent payload |
| Domain | defence.cdga.site | Historical domain impersonating India’s Controller General of Defence Accounts, associated with HACKERAI distribution |
| Domain | appstoore.solutions | PATCHCORD command-and-control domain |
| Domain | www.appstoore.solutions | Related PATCHCORD command-and-control domain |
| Domain | afghantelecom.site | Campaign infrastructure domain impersonating Afghan Telecom |
| Domain | afghanistanupdates.site | Campaign infrastructure domain impersonating an Afghan government updates portal |
| Domain | www.afghanistanupdates.site | Related campaign infrastructure domain |
| Domain | caprispine.health | Campaign infrastructure domain impersonating a healthcare organization |
| Domain | www.caprispine.health | Related campaign infrastructure domain |
| Domain | servicesindia.services | Campaign infrastructure domain |
| Domain | www.servicesindia.services | Related campaign infrastructure domain |
| Domain | zala-aer.info | Campaign infrastructure domain |
| Domain | www.zala-aer.info | Related campaign infrastructure domain |
| Domain | nicservice.org | Campaign infrastructure domain impersonating an Indian government service |
| Domain | www.nicservice.org | Related campaign infrastructure domain |
| Domain | nic-support.site | Domain used to serve SHEETCORD |
| Domain | appstoore.duckdns.org | Historical dynamic DNS domain associated with the infrastructure |
| IP address | 46.30.188.13 | Command-and-control server associated with the campaign |
| File name | TMSAfghanTelecom.exe | Malicious installer used in the PATCHCORD delivery chain |
| SHA-256 | cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6 | Hash for TMSAfghanTelecom.exe |
| File name | AFTELVPNSetup.exe | Afghan Telecom VPN-themed malicious installer |
| SHA-256 | 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94 | Hash for AFTELVPNSetup.exe |
| File name | MDEBUpdateSetup.exe | Ministry of Defense-themed malicious installer |
| SHA-256 | 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668 | Hash for MDEBUpdateSetup.exe |
| File name | SystemHelper.vbs | SHEETCORD startup persistence script |
| User-Agent | Beacon1.0.0 | PATCHCORD HTTP user-agent string |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…