Judicial Targets Hit by COVERT RAT via Court Docs and GitHub Payloads
## Cybersecurity: COVERT RAT Phishing Campaign
Cybersecurity: COVERT RAT Phishing Campaign
A targeted spear-phishing campaign has been identified, leveraging fake court documents and GitHub-hosted payloads to deploy a Rust-based COVERT RAT against Argentina's judicial sector.
The attack utilizes a combination of Windows LNK shortcuts, BAT loaders, and PowerShell scripts to discreetly download and execute a payload named msedge_proxy.exe from GitHub. This operation, known as "Operation Covert Access," uses realistic Argentine federal court documents to deceive victims.
Targeted entities include federal courts, legal practitioners, government bodies related to justice, academic institutions, and legal advocacy groups within Argentina's judicial ecosystem. The attackers exploit the perceived trust of official communications to gain initial access and establish long-term positions within high-value legal environments.
The intrusion begins with spear-phishing emails that deliver a ZIP archive containing three files: a weaponized LNK shortcut, a BAT-based loader script, and a court-themed PDF decoy. When victims open the LNK file, PowerShell is executed from the system directory, bypassing execution policy and operating in hidden mode, while simultaneously displaying the benign-looking PDF to the user.
The BAT file then uses PowerShell to download a file named health-check.exe and save it as msedge_proxy.exe in the Microsoft Edge user data directory, adopting a trusted filename and location. The script ultimately executes msedge_proxy.exe , transitioning from loader activity to full RAT execution under the guise of legitimate browser-related behavior.
Once activated, msedge_proxy.exe performs extensive anti-virtualization, anti-sandbox, and anti-debugging checks. If these checks are passed, the malware collects system information and establishes a command-and-control channel. The RAT supports commands for persistence, file transfer, data harvesting, encryption, decryption, and privilege escalation.
This operation, known as "Operation Covert Access," uses realistic Argentine federal court documents to deceive victims.
Instructions are encoded before transmission and decoded on the target device, allowing the dynamic loading of modules for ransomware and credential theft. A specific command facilitates the removal of persistence mechanisms, providing attackers with both long-term access and a controlled exit strategy.
Organizations in legal and government sectors should enforce strict controls on LNK execution, restrict scriptable access to external repositories, and monitor for unusual PowerShell activity that originates from shortcuts and creates browser-named binaries in Edge profile paths.
SHA256 Name
13adde53bd767d17108786bcc1bc0707c2411a40f11d67dfa9ba1a2c62cc5cf3 Zip File
10bbc5e192c3d01100031634d4e93f0be4becbe0a63f3318dd353e0f318e43de juicio-grunt-posting.pdf
6ae4222728240a566a1ca8c8873eab3b0659a28437877e4450808264848ab01e health-check.bat
4612c90cdfb7e43b4e9afe2a37a82d8b925bab3fd3838b24ec73b0e775afdb75 msedge_proxy.exe
37e6da4c813557f09fa2336b43c9fbb4633e562952f5113f6a6a8f3c226854eb notas.pdf
Based on reporting by GBHackers.
