Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HACKERAI Malware Utilizes GitHub for Command Control

HACKERAI Malware Utilizes GitHub for Command Control

Posted on August 14, 2026 By CWS

A new cybersecurity threat, dubbed HACKERAI C2 Agent, has surfaced, employing GitHub Gists as a covert command-and-control channel. This method allows malicious traffic to blend with legitimate network activities, complicating detection efforts by organizations.

Espionage Campaigns in South Asia

The HACKERAI malware framework was discovered amid investigations into a broader espionage operation targeting telecom, government, and critical infrastructure sectors in South Asia. Attackers enticed victims with files masquerading as trusted services and software updates.

Security experts from Acronis have identified HACKERAI alongside two related malware families known as PATCHCORD and SHEETCORD, attributing the activity with moderate confidence to APT36, a Pakistan-linked threat group. This group is notorious for using malicious files and cloud-hosted services in campaigns aimed at regional governmental and defense entities.

Innovative Tactics and Techniques

Unlike traditional malware that relies on attacker-controlled servers, HACKERAI uses GitHub Gists to fetch instructions and upload data from compromised devices. This strategy makes investigations challenging as network traffic involving GitHub might be dismissed as routine by security teams.

The HACKERAI C2 Agent is capable of executing tasks downloaded from GitHub Gists and posting results back through the same platform. This malware can also collect system information, execute remote commands, and maintain persistence by modifying browser shortcuts, which allows it to operate discreetly.

Expanding Threat Landscape

The broader campaign linked to HACKERAI targets Afghan telecom firms and Indian organizations using deceptive installers and archives. One such lure posed as Afghan Telecom with a misleading ZIP file, while another pretended to be a Ministry of Defense update.

PATCHCORD, the primary implant, hijacks shortcuts for popular web browsers to ensure persistence, while SHEETCORD, a variant, employs Google Sheets instead of GitHub for command traffic. Researchers also discovered a staging server with phishing tools and multiple command-and-control frameworks, indicative of a multifaceted attack strategy.

Security Recommendations and Outlook

Organizations should be vigilant about unusual GitHub activity and ensure scrutiny of browser shortcuts and software installers from unverified sources. The report advises South Asian entities to be wary of phishing attempts targeting specific sectors and to monitor for suspicious indicators.

The ongoing use of legitimate cloud services for malicious purposes underscores the evolving nature of cyber threats, emphasizing the need for robust security measures and continuous vigilance to protect against sophisticated attacks like those orchestrated by HACKERAI.

Cyber Security News Tags:APT36, cyber threat, Cybersecurity, Espionage, GitHub, Government, HACKERAI, Malware, South Asia, Telecom

Post navigation

Previous Post: RingCentral Data Breach Exposes 1.6 Million Records
Next Post: Trivy, Not LiteLLM, Caused 2,500 Organization Breach

Related Posts

Delta Flight Wi-Fi Hacked Amid Cybersecurity Conference Delta Flight Wi-Fi Hacked Amid Cybersecurity Conference Cyber Security News
CISA Warns of Fortinet FortiOS Hard-Coded Credentials Vulnerability Exploited in Attacks CISA Warns of Fortinet FortiOS Hard-Coded Credentials Vulnerability Exploited in Attacks Cyber Security News
Critical React Router Vulnerability Let Attackers Access or Modify Server Files Critical React Router Vulnerability Let Attackers Access or Modify Server Files Cyber Security News
ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack ShadowV2 Botnet Exploits Docker Containers on AWS to Turn Thems as Infected System for DDoS Attack Cyber Security News
Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Cyber Security News
Axis Camera Server Vulnerabilities Exposes Thousands of Organizations to Attack Axis Camera Server Vulnerabilities Exposes Thousands of Organizations to Attack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK NCSC Calls for Immediate Citrix NetScaler Vulnerability Patching
  • 2026 CISO Forum Virtual Summit Seeks Presentation Proposals
  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK NCSC Calls for Immediate Citrix NetScaler Vulnerability Patching
  • 2026 CISO Forum Virtual Summit Seeks Presentation Proposals
  • Bitget Security Breach Results in $387 Million Loss
  • Nvidia Launches AI Safety Platform with Hardware Watchdog
  • Major Cybersecurity Incidents: Crypto Heist and Citrix Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark