Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HACKERAI Malware Utilizes GitHub for Command Control

HACKERAI Malware Utilizes GitHub for Command Control

Posted on August 14, 2026 By CWS

A new cybersecurity threat, dubbed HACKERAI C2 Agent, has surfaced, employing GitHub Gists as a covert command-and-control channel. This method allows malicious traffic to blend with legitimate network activities, complicating detection efforts by organizations.

Espionage Campaigns in South Asia

The HACKERAI malware framework was discovered amid investigations into a broader espionage operation targeting telecom, government, and critical infrastructure sectors in South Asia. Attackers enticed victims with files masquerading as trusted services and software updates.

Security experts from Acronis have identified HACKERAI alongside two related malware families known as PATCHCORD and SHEETCORD, attributing the activity with moderate confidence to APT36, a Pakistan-linked threat group. This group is notorious for using malicious files and cloud-hosted services in campaigns aimed at regional governmental and defense entities.

Innovative Tactics and Techniques

Unlike traditional malware that relies on attacker-controlled servers, HACKERAI uses GitHub Gists to fetch instructions and upload data from compromised devices. This strategy makes investigations challenging as network traffic involving GitHub might be dismissed as routine by security teams.

The HACKERAI C2 Agent is capable of executing tasks downloaded from GitHub Gists and posting results back through the same platform. This malware can also collect system information, execute remote commands, and maintain persistence by modifying browser shortcuts, which allows it to operate discreetly.

Expanding Threat Landscape

The broader campaign linked to HACKERAI targets Afghan telecom firms and Indian organizations using deceptive installers and archives. One such lure posed as Afghan Telecom with a misleading ZIP file, while another pretended to be a Ministry of Defense update.

PATCHCORD, the primary implant, hijacks shortcuts for popular web browsers to ensure persistence, while SHEETCORD, a variant, employs Google Sheets instead of GitHub for command traffic. Researchers also discovered a staging server with phishing tools and multiple command-and-control frameworks, indicative of a multifaceted attack strategy.

Security Recommendations and Outlook

Organizations should be vigilant about unusual GitHub activity and ensure scrutiny of browser shortcuts and software installers from unverified sources. The report advises South Asian entities to be wary of phishing attempts targeting specific sectors and to monitor for suspicious indicators.

The ongoing use of legitimate cloud services for malicious purposes underscores the evolving nature of cyber threats, emphasizing the need for robust security measures and continuous vigilance to protect against sophisticated attacks like those orchestrated by HACKERAI.

Cyber Security News Tags:APT36, cyber threat, Cybersecurity, Espionage, GitHub, Government, HACKERAI, Malware, South Asia, Telecom

Post navigation

Previous Post: RingCentral Data Breach Exposes 1.6 Million Records
Next Post: Trivy, Not LiteLLM, Caused 2,500 Organization Breach

Related Posts

Seedworm Exploits Signed Software for Covert Attacks Seedworm Exploits Signed Software for Covert Attacks Cyber Security News
SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack Cyber Security News
Threat Actors Weaponizes LNK Files to Deploy RedLoader Malware on Windows Systems Threat Actors Weaponizes LNK Files to Deploy RedLoader Malware on Windows Systems Cyber Security News
Cloudflare Confirms Recent 1.1.1.1 DNS Outage Caused by BGP Attack or Hijack Cloudflare Confirms Recent 1.1.1.1 DNS Outage Caused by BGP Attack or Hijack Cyber Security News
Chinese Cyber Group Targets US Medical Research via REDCap Chinese Cyber Group Targets US Medical Research via REDCap Cyber Security News
BlueNoroff Targets Cryptocurrency Through Fake Zoom Meetings BlueNoroff Targets Cryptocurrency Through Fake Zoom Meetings Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack
  • MessiahGPT AI Tool Fuels Cybercrime with Ransomware
  • Trivy, Not LiteLLM, Caused 2,500 Organization Breach
  • HACKERAI Malware Utilizes GitHub for Command Control
  • RingCentral Data Breach Exposes 1.6 Million Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack
  • MessiahGPT AI Tool Fuels Cybercrime with Ransomware
  • Trivy, Not LiteLLM, Caused 2,500 Organization Breach
  • HACKERAI Malware Utilizes GitHub for Command Control
  • RingCentral Data Breach Exposes 1.6 Million Records

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark