logo

Judicial Targets Hit by COVERT RAT via Court Docs and GitHub Payloads

ID: 2b702dde-67af-5b6a-9c49-0820553d9078

STIX ID: report--2b702dde-67af-5b6a-9c49-0820553d9078

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Attackers conducted a focused spear‑phishing campaign (“Operation Covert Access”) targeting Argentina’s judicial sector using realistic court‑themed PDFs and a ZIP containing a disguised LNK, a BAT loader, and a PDF decoy; the LNK launches PowerShell to download a GitHub‑hosted Rust-based RAT (msedge_proxy.exe) placed in an Edge profile path. The RAT includes extensive anti‑analysis checks, modular capabilities for persistence, data harvesting, file upload/download, encryption and credential theft, and the report provides SHA256 IOCs and mitigation recommendations for legal and government defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.