Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

Operation Covert Access is a targeted attack campaign impacting Argentina's judicial system. Utilizing fake court documents, attackers deploy a Rust-built Remote Access Trojan (RAT) named COVERT RAT through spear-phishing emails that closely resemble…

Operation Covert Access is a targeted attack campaign impacting Argentina's judicial system. Utilizing fake court documents, attackers deploy a Rust-built Remote Access Trojan (RAT) named COVERT RAT through spear-phishing emails that closely resemble legitimate federal court communications.

The campaign's primary vector is spear-phishing emails carrying a ZIP archive. This archive contains three components: a Windows shortcut (LNK) file, a batch loader script, and a judicial PDF decoy. When executed, the LNK file triggers a PowerShell script in hidden mode, initiating a series of processes to install the RAT. The malware is disguised as msedge_proxy.exe within Microsoft Edge’s user data folder.

The LNK file opens and executes a hidden PowerShell command. This triggers the health-check.bat script, which downloads the RAT payload from a GitHub repository. The payload is executed with PowerShell's Start-Process command, embedding itself as msedge_proxy.exe .

Operation Covert Access is a targeted attack campaign impacting Argentina's judicial system.
Rebecca Stone · Thehackingpost

Once installed, COVERT RAT provides attackers with persistent control over the infected systems, allowing for credential harvesting, privilege escalation, and encrypted file operations. The malware connects to a command-and-control server at 181.231.253.69:4444 to receive encoded instructions. Notably, it includes a cleanup feature that erases all traces post-operation, complicating forensic analysis.

Ensure antivirus software is up to date and real-time protection is enabled. Avoid opening email attachments from unverified senders, especially if they are compressed archives. Do not click on suspicious links or download files from unofficial sources. Regularly monitor running processes and investigate unfamiliar entries such as msedge_proxy.exe . Avoid using cracked or pirated software.

Advertisement

For further details, refer to the Point Wild analysis and consider additional resources on cybersecurity best practices.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories