logo

HACKERAI Malware: GitHub Gists Used for Covert C2

ID: 42cf3532-5ec4-5815-9661-941242a0bc0a

STIX ID: report--42cf3532-5ec4-5815-9661-941242a0bc0a

Feed Name: CyberNexora News

Threat Score
75/100

Date Published: 2026-08-14

Date Updated: 2026-08-14

Author: Debolina Barik

...
...

Acronis research describes a newly identified malware framework named HACKERAI that uses legitimate GitHub Gists as a covert C2 channel to receive commands and exfiltrate data; the campaign reportedly targeted telecom, government, defense, energy and critical infrastructure organizations in South Asia and is assessed with moderate confidence as linked to APT36 (Transparent Tribe). The report outlines capabilities (system-info collection, remote command execution, persistence via browser shortcut changes), defensive recommendations, and notes the absence of machine-readable IoCs in the published summary.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.