HACKERAI C2 Agent is a malware framework used in a South Asia-focused espionage campaign assessed with moderate confidence to overlap with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked actor. It is associated with operations targeting telecom, government, defense, energy, and other critical infrastructure organizations, including Afghan telecom-themed targeting and lures impersonating government or software update workflows.
The malware uses GitHub Gists as a covert command-and-control channel rather than relying solely on conventional attacker-controlled infrastructure. It retrieves tasking from GitHub-hosted content and uploads stolen results through the same service, blending malicious traffic with legitimate cloud activity. Reported functionality includes system fingerprinting, collection of basic host information, remote command execution, and data exfiltration. It also establishes persistence by hijacking browser shortcuts so the malware executes before the legitimate browser while still launching the expected browser application to reduce user suspicion.
HACKERAI C2 Agent shares tradecraft and functional overlap with related malware families in the same campaign, notably PATCHCORD and SHEETCORD, which similarly emphasize covert command-and-control and browser-shortcut abuse. Analysis has noted implementation artifacts consistent with AI-assisted development, including unusual code comments, debugging remnants, and redundant logic. The malware has been distributed through themed installer and archive lures tied to the broader espionage operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A third malware family, HACKERAI C2 Agent, shows signs of AI-assisted development and uses GitHub Gists for C2.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
SHEETCORD, a Go-based implant... abusing Google Sheets for C2 communication... HACKERAI C2 Agent... replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists, using dedicated upload and download functions for both tasking and data exfiltration.
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
The implant receives an encoded payload as part of the tasking response, decodes it using the same custom Base64 alphabet and decrypts it using a XOR-based routine with a key derived from the session context.
The installer contains version metadata designed to impersonate Afghan Telecom, with the CompanyName, FileDescription, and ProductName fields set to "Afghan Telecom," "TMS Afghan Telecom Setup," and "TMS Afghan Telecom," respectively.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
The implant fingerprints the victim system by collecting the hostname, username, operating system version, process identifier, executable path and process name before constructing a JSON registration payload for the C2 server.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
This one drops the traditional web server entirely and instead uses the Google Sheets API for command and control, creating a dedicated spreadsheet tab for each victim to send and receive instructions.
The registration payload is sent as an HTTP POST request to the root path of the C2 server... the implant enters a polling loop, sending GET requests to the constructed /api.jsp tasking URL at regular intervals.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family or C2 agent that appears AI-assisted in development and uses GitHub Gists for command-and-control.
A malware family that uses GitHub Gists for command-and-control and reportedly contains indicators of AI-assisted development, including debug messages, AI-style comments, and redundant cryptographic logic.
A named command-and-control implant/agent associated with the PATCHCORD espionage campaign and used by APT36/Transparent Tribe.
A malware framework/backdoor that uses GitHub Gists for command-and-control and data exfiltration. It can collect system information, execute remote commands, upload results, and establish persistence by hijacking browser shortcuts so it launches before the legitimate browser.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.