Cyber Security News

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.

The technique lets operators blend malicious traffic with a service that many organizations allow on their networks.

The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia.

Victims were lured with files that impersonated trusted telecom services, government updates, and software installers.

Researchers at Acronis identified HACKERAI alongside two related malware families, PATCHCORD and SHEETCORD.

The activity is assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor.

Previous reporting has also documented the group’s use of malicious files and cloud-hosted services in campaigns targeting regional government and defense interests. APT36 attacks Windows systems

Acronis said in a report shared with Cyber Security News (CSN) that the HACKERAI stands out because it does not rely on a typical attacker-controlled server for its command-and-control channel.

Afghan Telecom–themed installer metadata (Source – Acronis)

Instead, it uses GitHub Gists, a legitimate feature designed for sharing small pieces of text and code, to retrieve instructions and upload information from infected devices.

This approach can make investigations harder. Network defenders may see connections to GitHub and assume they are harmless, while the malware uses that same trusted service to maintain contact with its operators.

The campaign also shows how attackers are combining familiar delivery tricks with new communication methods.

HACKERAI Malware

The HACKERAI C2 Agent includes functions for both downloading tasks and uploading collected information through GitHub Gists.

In practical terms, an infected machine can check a Gist for instructions, carry out those instructions, and send results back through the same service.

The malware can gather basic information about a compromised system, run commands remotely, and establish persistence by altering browser shortcuts.

That shortcut abuse allows the malware to start before the legitimate browser opens, while still launching the real browser so the victim may not notice anything unusual.

Afghan Telecom TMS request portal (Source – Acronis)

Researchers also found signs that HACKERAI may have been developed with help from AI coding tools.

The sample contained AI-style comments, debugging messages, test code, a duplicated XOR routine using the same 0xAB key, and a hardcoded GitHub personal access token.

The use of legitimate cloud platforms is not new, but it remains effective because it complicates simple block-listing decisions.

A related report on the SHEETCREEP Google Sheets channel showed how threat actors can use ordinary online services to hide command traffic among normal business activity.

The HACKERAI was discovered through historical infrastructure linked to the larger operation.

Researchers found that a domain impersonating India’s Controller General of Defence Accounts had been used to distribute the framework before the newer PATCHCORD campaign emerged.

Campaign Expands Across South Asia

The wider campaign used fraudulent installers and archives to target Afghan telecom providers and Indian organizations.

One lure impersonated Afghan Telecom through a ZIP archive named TelecomTMS, while another posed as a Ministry of Defense employee breach update.

PATCHCORD, the main implant, establishes persistence by hijacking shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox.

SHEETCORD, a Go-based variant, expands this approach to Brave, Opera, and Vivaldi, while using Google Sheets rather than GitHub Gists for command traffic.

The researchers also found an exposed staging server containing phishing archives, credential theft tools, exploit code, and several command-and-control frameworks.

That discovery points to an operator preparing multiple campaigns at once, rather than relying on a single malware family or delivery route.

SuperShell login panel (Source – Acronis)

For organizations, the immediate concern is not GitHub Gists alone but suspicious behavior around them.

Security teams should investigate unexpected GitHub activity from endpoints, watch for browser shortcuts whose targets have been changed, and verify software installers received through email, messaging apps, or unfamiliar websites.

The report recommends that organizations across South Asia remain alert for sector-specific phishing attempts and monitor the listed indicators.

Staff should be especially cautious of ZIP files and installers that claim to be VPN clients, telecom tools, government updates, or urgent security software.

Similar social-engineering activity has also been seen in APT36 defense phishing campaigns. The campaign infrastructure was still active at the time of publication.

Its combination of phishing lures, shortcut hijacking, AI-assisted development patterns, and cloud-based control channels highlights a continuing shift toward tools that are easier to build and harder to separate from legitimate internet traffic.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-25674d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2HACKERAI C2 Agent executable hash
File nameAgent.exeHACKERAI C2 Agent payload
Domaindefence.cdga.siteHistorical domain impersonating India’s Controller General of Defence Accounts, associated with HACKERAI distribution
Domainappstoore.solutionsPATCHCORD command-and-control domain
Domainwww.appstoore.solutionsRelated PATCHCORD command-and-control domain
Domainafghantelecom.siteCampaign infrastructure domain impersonating Afghan Telecom
Domainafghanistanupdates.siteCampaign infrastructure domain impersonating an Afghan government updates portal
Domainwww.afghanistanupdates.siteRelated campaign infrastructure domain
Domaincaprispine.healthCampaign infrastructure domain impersonating a healthcare organization
Domainwww.caprispine.healthRelated campaign infrastructure domain
Domainservicesindia.servicesCampaign infrastructure domain
Domainwww.servicesindia.servicesRelated campaign infrastructure domain
Domainzala-aer.infoCampaign infrastructure domain
Domainwww.zala-aer.infoRelated campaign infrastructure domain
Domainnicservice.orgCampaign infrastructure domain impersonating an Indian government service
Domainwww.nicservice.orgRelated campaign infrastructure domain
Domainnic-support.siteDomain used to serve SHEETCORD
Domainappstoore.duckdns.orgHistorical dynamic DNS domain associated with the infrastructure
IP address46.30.188.13Command-and-control server associated with the campaign
File nameTMSAfghanTelecom.exeMalicious installer used in the PATCHCORD delivery chain
SHA-256cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6Hash for TMSAfghanTelecom.exe
File nameAFTELVPNSetup.exeAfghan Telecom VPN-themed malicious installer
SHA-2561774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94Hash for AFTELVPNSetup.exe
File nameMDEBUpdateSetup.exeMinistry of Defense-themed malicious installer
SHA-256378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668Hash for MDEBUpdateSetup.exe
File nameSystemHelper.vbsSHEETCORD startup persistence script
User-AgentBeacon1.0.0PATCHCORD HTTP user-agent string

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago