HACKERAI Malware: GitHub Gists Used for Covert C2
ID: 42cf3532-5ec4-5815-9661-941242a0bc0a
STIX ID: report--42cf3532-5ec4-5815-9661-941242a0bc0a
Feed Name: CyberNexora News
Acronis research describes a newly identified malware framework named HACKERAI that uses legitimate GitHub Gists as a covert C2 channel to receive commands and exfiltrate data; the campaign reportedly targeted telecom, government, defense, energy and critical infrastructure organizations in South Asia and is assessed with moderate confidence as linked to APT36 (Transparent Tribe). The report outlines capabilities (system-info collection, remote command execution, persistence via browser shortcut changes), defensive recommendations, and notes the absence of machine-readable IoCs in the published summary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
