Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Judicial Targets Hit by COVERT RAT via Court Docs and GitHub Payloads

## Cybersecurity: COVERT RAT Phishing Campaign

Cybersecurity: COVERT RAT Phishing Campaign

A targeted spear-phishing campaign has been identified, leveraging fake court documents and GitHub-hosted payloads to deploy a Rust-based COVERT RAT against Argentina's judicial sector.

The attack utilizes a combination of Windows LNK shortcuts, BAT loaders, and PowerShell scripts to discreetly download and execute a payload named msedge_proxy.exe from GitHub. This operation, known as "Operation Covert Access," uses realistic Argentine federal court documents to deceive victims.

Targeted entities include federal courts, legal practitioners, government bodies related to justice, academic institutions, and legal advocacy groups within Argentina's judicial ecosystem. The attackers exploit the perceived trust of official communications to gain initial access and establish long-term positions within high-value legal environments.

The intrusion begins with spear-phishing emails that deliver a ZIP archive containing three files: a weaponized LNK shortcut, a BAT-based loader script, and a court-themed PDF decoy. When victims open the LNK file, PowerShell is executed from the system directory, bypassing execution policy and operating in hidden mode, while simultaneously displaying the benign-looking PDF to the user.

The BAT file then uses PowerShell to download a file named health-check.exe and save it as msedge_proxy.exe in the Microsoft Edge user data directory, adopting a trusted filename and location. The script ultimately executes msedge_proxy.exe , transitioning from loader activity to full RAT execution under the guise of legitimate browser-related behavior.

Once activated, msedge_proxy.exe performs extensive anti-virtualization, anti-sandbox, and anti-debugging checks. If these checks are passed, the malware collects system information and establishes a command-and-control channel. The RAT supports commands for persistence, file transfer, data harvesting, encryption, decryption, and privilege escalation.

This operation, known as "Operation Covert Access," uses realistic Argentine federal court documents to deceive victims.
Daniel Brooks · Thehackingpost

Instructions are encoded before transmission and decoded on the target device, allowing the dynamic loading of modules for ransomware and credential theft. A specific command facilitates the removal of persistence mechanisms, providing attackers with both long-term access and a controlled exit strategy.

Organizations in legal and government sectors should enforce strict controls on LNK execution, restrict scriptable access to external repositories, and monitor for unusual PowerShell activity that originates from shortcuts and creates browser-named binaries in Edge profile paths.

SHA256 Name

13adde53bd767d17108786bcc1bc0707c2411a40f11d67dfa9ba1a2c62cc5cf3 Zip File

Advertisement

10bbc5e192c3d01100031634d4e93f0be4becbe0a63f3318dd353e0f318e43de juicio-grunt-posting.pdf

6ae4222728240a566a1ca8c8873eab3b0659a28437877e4450808264848ab01e health-check.bat

4612c90cdfb7e43b4e9afe2a37a82d8b925bab3fd3838b24ec73b0e775afdb75 msedge_proxy.exe

37e6da4c813557f09fa2336b43c9fbb4633e562952f5113f6a6a8f3c226854eb notas.pdf

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories