A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that many organizations allow on their networks. The malware appeared during an investigation into a wider espionage campaign aimed at telecom, government, defense, energy, and critical infrastructure organizations in South Asia. Victims were lured with files that impersonated trusted telecom services, government updates, and software installers. Researchers at Acronis identified HACKERAI alongside two related malware families, PATCHCORD and SHEETCORD. The activity is assessed with moderate confidence to overlap...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!