HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel (opens in a new tab)
Why readGives you three new malware family names and a C2 channel, GitHub Gists, that most egress policies and proxy allowlists let through untouched.
Acronis researchers documented a framework they call HACKERAI C2 Agent that reads operator commands from and exfiltrates data to GitHub Gists, alongside two related families named PATCHCORD and SHEETCORD. The campaign targeted telecom, government, defense, energy, and critical infrastructure in South Asia using lures posing as telecom services, government updates, and software installers, and is tied with moderate confidence to APT36 or a closely related Pakistan-linked actor. This is a rewrite of the Acronis report rather than primary research, so treat the vendor writeup as the source for indicators; the useful takeaway is that gist.github.com traffic from workstations deserves the same scrutiny as any other cloud C2 fronting service.
Indicators4
- Hashes
74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d61774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668