HACKERAI C2 Agent is a malware framework used in a South Asia-focused espionage campaign targeting telecommunications, government, defense, energy, and other critical infrastructure organizations. The activity has been assessed with moderate confidence as overlapping with APT36, also known as Transparent Tribe, or a closely related Pakistan-linked threat actor. The malware represents an earlier implant in an operational cluster that also includes PATCHCORD and SHEETCORD, reflecting a broader shift toward covert cloud-based command-and-control channels.
HACKERAI C2 Agent uses GitHub Gists as its command-and-control mechanism rather than relying on a conventional attacker-operated server. It retrieves tasking from Gists and uploads stolen results through the same service, blending malicious traffic with legitimate cloud activity. Reported capabilities include host fingerprinting, collection of basic system information, remote command execution, and data exfiltration. It also establishes persistence by hijacking browser shortcuts so that the malware launches before the legitimate browser while still opening the expected browser application to reduce user suspicion.
The malware has been associated with lure-based delivery in the form of fraudulent installers and archives themed around telecom services, government updates, and defense-related subjects. Historical distribution was linked to infrastructure impersonating an Indian defense accounting entity. Analysis also noted signs consistent with AI-assisted development, including AI-style comments, debugging artifacts, and duplicated code patterns. Within the broader campaign, HACKERAI C2 Agent appears to share tradecraft and core functionality with PATCHCORD and SHEETCORD, particularly around system reconnaissance, remote execution, and browser shortcut abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This research details TRU's analysis of the PATCHCORD, SHEETCORD and HACKERAI C2 Agent malware families, their C2 mechanisms and the supporting infrastructure.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
SHEETCORD, a Go-based implant... abusing Google Sheets for C2 communication... HACKERAI C2 Agent... replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists, using dedicated upload and download functions for both tasking and data exfiltration.
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
PATCHCORD establishes persistence by hijacking browser shortcuts... Once confirmed, the implant creates a backup of the original shortcut... and rewrites the shortcut... sets the shortcut's target path to the implant's own executable... As a result, every time the user clicks a browser shortcut, PATCHCORD executes first.
The implant receives an encoded payload as part of the tasking response, decodes it using the same custom Base64 alphabet and decrypts it using a XOR-based routine with a key derived from the session context.
The installer contains version metadata designed to impersonate Afghan Telecom, with the CompanyName, FileDescription, and ProductName fields set to "Afghan Telecom," "TMS Afghan Telecom Setup," and "TMS Afghan Telecom," respectively.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
The implant fingerprints the victim system by collecting the hostname, username, operating system version, process identifier, executable path and process name before constructing a JSON registration payload for the C2 server.
The implant checks for VirtualBox and VMware device handles... verifies the system has more than one processor and at least 2GB of RAM... scans active TCP connections for ports commonly associated with analysis tools... monitors cursor movement and user input to detect automated sandbox environments. If any check is triggered, the implant enters a randomized sleep loop of 30 to 90 seconds.
Instead, it uses GitHub Gists, a legitimate feature designed for sharing small pieces of text and code, to retrieve instructions and upload information from infected devices. | A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data.
The registration payload is sent as an HTTP POST request to the root path of the C2 server... the implant enters a polling loop, sending GET requests to the constructed /api.jsp tasking URL at regular intervals.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named command-and-control implant/agent associated with the PATCHCORD espionage campaign and used by APT36/Transparent Tribe.
A malware framework/backdoor that uses GitHub Gists for command-and-control and data exfiltration. It can collect system information, execute remote commands, upload results, and establish persistence by hijacking browser shortcuts so it launches before the legitimate browser.
A previously undocumented malware framework with signs of AI-assisted development. It shares system fingerprinting, remote command execution, and browser shortcut hijacking with PATCHCORD and SHEETCORD, but uses GitHub Gists for tasking and data exfiltration. It also includes basic anti-analysis and junk-operation delays.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.