A newly discovered malware framework called HACKERAI C2 Agent is utilizing GitHub Gists as a covert communication channel for attackers to execute commands and steal data.

Indicators of Compromise (IoCs): - Type Indicator Description - SHA-256 74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2 HACKERAI C2 Agent executable hash - File name Agent.exe HACKERAI C2 Agent payload - Domain defence.cdga.site Historical domain impersonating India’s Controller General of Defence Accounts, associated with HACKERAI distribution - Domain appstoore.solutions PATCHCORD command-and-control domain - Domain www.appstoore.solutions Related PATCHCORD command-and-control domain - Domain afghantelecom.site Campaign infrastructure domain impersonating Afghan Telecom - Domain afghanistanupdates.site Campaign infrastructure domain impersonating an Afghan government updates portal - Domain www.afghanistanupdates.site Related campaign infrastructure domain - Domain caprispine.health Campaign infrastructure domain impersonating a healthcare organization - Domain www.caprispine.health Related campaign infrastructure domain - Domain servicesindia.services Campaign infrastructure domain - Domain www.servicesindia.services Related campaign infrastructure domain - Domain zala-aer.info Campaign infrastructure domain - Domain www.zala-aer.info Related campaign infrastructure domain - Domain nicservice.org Campaign infrastructure domain impersonating an Indian government service - Domain www.nicservice.org Related campaign infrastructure domain - Domain nic-support.site Domain used to serve SHEETCORD - Domain appstoore.duckdns.org Historical dynamic DNS domain associated with the infrastructure - IP address 46.30.188.13 Command-and-control server associated with the campaign - File name TMSAfghanTelecom.exe Malicious installer used in the PATCHCORD delivery chain - SHA-256 cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6 Hash for TMSAfghanTelecom.exe - File name AFTELVPNSetup.exe Afghan Telecom VPN-themed malicious installer - SHA-256 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94 Hash for AFTELVPNSetup.exe - File name MDEBUpdateSetup.exe Ministry of Defense-themed malicious installer - SHA-256 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668 Hash for MDEBUpdateSetup.exe - File name SystemHelper.vbs SHEETCORD startup persistence script - User-Agent Beacon1.0.0 PATCHCORD HTTP user-agent string