A new cybersecurity threat, dubbed HACKERAI C2 Agent, has surfaced, employing GitHub Gists as a covert command-and-control channel. This method allows malicious traffic to blend with legitimate network activities, complicating detection efforts by organizations.
Espionage Campaigns in South Asia
The HACKERAI malware framework was discovered amid investigations into a broader espionage operation targeting telecom, government, and critical infrastructure sectors in South Asia. Attackers enticed victims with files masquerading as trusted services and software updates.
Security experts from Acronis have identified HACKERAI alongside two related malware families known as PATCHCORD and SHEETCORD, attributing the activity with moderate confidence to APT36, a Pakistan-linked threat group. This group is notorious for using malicious files and cloud-hosted services in campaigns aimed at regional governmental and defense entities.
Innovative Tactics and Techniques
Unlike traditional malware that relies on attacker-controlled servers, HACKERAI uses GitHub Gists to fetch instructions and upload data from compromised devices. This strategy makes investigations challenging as network traffic involving GitHub might be dismissed as routine by security teams.
The HACKERAI C2 Agent is capable of executing tasks downloaded from GitHub Gists and posting results back through the same platform. This malware can also collect system information, execute remote commands, and maintain persistence by modifying browser shortcuts, which allows it to operate discreetly.
Expanding Threat Landscape
The broader campaign linked to HACKERAI targets Afghan telecom firms and Indian organizations using deceptive installers and archives. One such lure posed as Afghan Telecom with a misleading ZIP file, while another pretended to be a Ministry of Defense update.
PATCHCORD, the primary implant, hijacks shortcuts for popular web browsers to ensure persistence, while SHEETCORD, a variant, employs Google Sheets instead of GitHub for command traffic. Researchers also discovered a staging server with phishing tools and multiple command-and-control frameworks, indicative of a multifaceted attack strategy.
Security Recommendations and Outlook
Organizations should be vigilant about unusual GitHub activity and ensure scrutiny of browser shortcuts and software installers from unverified sources. The report advises South Asian entities to be wary of phishing attempts targeting specific sectors and to monitor for suspicious indicators.
The ongoing use of legitimate cloud services for malicious purposes underscores the evolving nature of cyber threats, emphasizing the need for robust security measures and continuous vigilance to protect against sophisticated attacks like those orchestrated by HACKERAI.
