{"id":11427,"date":"2026-03-18T10:03:40","date_gmt":"2026-03-18T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/18\/attackers-abuse-court-documents-github-payloads-to-infect-judicial-targets-with-covert-rat\/"},"modified":"2026-03-18T10:03:40","modified_gmt":"2026-03-18T10:03:40","slug":"attackers-abuse-court-documents-github-payloads-to-infect-judicial-targets-with-covert-rat","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/18\/attackers-abuse-court-documents-github-payloads-to-infect-judicial-targets-with-covert-rat\/","title":{"rendered":"Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT"},"content":{"rendered":"<p>    Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new wave of targeted attacks is quietly hitting Argentina\u2019s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. <\/p>\n<p>The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan known as COVERT RAT via spear-phishing emails that closely mimic genuine federal court communications. <\/p>\n<p>Once inside a system, the threat gives attackers persistent control over the infected machine and everything stored on it.<\/p>\n<p>The operation takes direct aim at Argentina\u2019s legal ecosystem \u2014 federal courts, law practitioners, government justice agencies, academic institutions, and advocacy organizations. <\/p>\n<p>Attackers constructed phishing emails around real Argentine federal court rulings covering preventive detention reviews, knowing that judicial professionals would not question the legitimacy of such documents. <\/p>\n<p>That careful choice of subject matter is precisely what makes this campaign so effective \u2014 it exploits trust in the legal process rather than relying on curiosity or fear alone.<\/p>\n<p><a href=\"https:\/\/www.pointwild.com\/threat-intelligence\/covert-rat-phishing-campaign\/\" id=\"https:\/\/www.pointwild.com\/threat-intelligence\/covert-rat-phishing-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Point Wild analysts identified and investigated the operation<\/a>, building on foundational research published by Seqrite. <\/p>\n<p>Their work provided an in-depth breakdown of the PowerShell execution flow, payload retrieval techniques, and the masquerading methods attackers used throughout each stage. <\/p>\n<p>The analysis confirmed that this is not a simple one-step attack but a layered intrusion effort crafted to remain unnoticed inside institutional networks for as long as possible.<\/p>\n<p>The threat goes far beyond basic surveillance. COVERT RAT connects back to a <a href=\"https:\/\/cybersecuritynews.com\/chinese-threat-actors-hosted-18000-active-c2-servers\/\" id=\"139740\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control server<\/a> at 181.231.253.69:4444, from which attackers can issue encoded instructions covering everything from file theft to ransomware deployment. <\/p>\n<p>Its modular design supports credential harvesting, privilege escalation, encrypted file operations, and persistent re-access. <\/p>\n<p>What makes it particularly concerning is its built-in cleanup capability \u2014 when operators are finished, a single command erases every trace of the malware, making post-incident forensics significantly harder.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjbuXlynyEZUAwrZDWj_H-9CQTg7sfBLMEKxThs1f0wKve6nkXP3fFb7W7DA0jTZU2gmFKR4tzftp7epvHL3oyFwMdForH5wRnHYHMAoXxJql0gmIpNmdopoXyqfpR43g7eI3YcQr4HCpfoc3ww6TGjChHCI_eqjL6lNmiiLmfFctOH_NLMnTmqb9HRMeU\/s16000\/Execution%2520flow%2520%28Source%2520-%2520Point%2520Wild%29.webp?ssl=1\" alt=\"Execution flow (Source - Point Wild)\"><figcaption class=\"wp-element-caption\">Execution flow (Source \u2013 Point Wild)<\/figcaption><\/figure>\n<\/div>\n<p>The delivery method behind this campaign is deliberately layered. A phishing email drops a ZIP archive containing three components: a Windows shortcut (LNK) file, a batch loader script, and a convincing judicial PDF decoy. <\/p>\n<p>When the target opens the shortcut, the malicious script runs quietly in the background while the decoy PDF opens normally in the foreground. <\/p>\n<p>The final payload then hides itself as\u00a0<code>msedge_proxy.exe<\/code>\u00a0within Microsoft Edge\u2019s <a href=\"https:\/\/cybersecuritynews.com\/blisk-web-browser\/\" id=\"2008\" target=\"_blank\" rel=\"noreferrer noopener\">user data<\/a> folder \u2014 a calculated move to blend in with trusted system processes.<\/p>\n<h2 class=\"wp-block-heading\" id=\"multi-stage-infection-mechanism\"><strong>Multi-Stage Infection Mechanism<\/strong><\/h2>\n<p>When the recipient opens the shortcut file, named\u00a0<code>juicio-grunt-posting.pdf.lnk<\/code>\u00a0and dressed up with a PDF icon, it silently invokes PowerShell with the execution policy disabled and hidden mode enabled. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEivJgYKdK4LBcVdbwTFURF_qG60uLexkklDAtapthDObDOse2ncXD8m8snLetanaXqGsw8CFocpRwKSWtVrbvDOrNPiUhvMbKrwh8IqK0yUaW-pqvGs89RfxhYqpPBptjmhyDV2AMF2IoUCy4HfLWHKdpMnlvECBbcdM9ARv2Pw3P_YVZcYl6kLDVJH-sU\/s16000\/Zip%2520contains%2520LNK%2C%2520PDF%2520and%2520BAT%2520files%2520%28Source%2520-%2520Point%2520Wild%29.webp?ssl=1\" alt=\"Zip contains LNK, PDF and BAT files (Source - Point Wild)\"><figcaption class=\"wp-element-caption\">Zip contains LNK, PDF and BAT files (Source \u2013 Point Wild)<\/figcaption><\/figure>\n<\/div>\n<p>This immediately triggers the batch loader,\u00a0<code>health-check.bat<\/code>, which reaches out to a GitHub-hosted repository and downloads the RAT payload. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj5mNCNJaOaHL8Igy6LwWBse-rz4Z4oSJdct43SMKWnAL8jviI2u5jLPdDwlSraz-kEjiNW_wIzvtyyui_OXnDkFgbd3YWcc1v9LLCsM9HAp6ofuTWnb0_yAriKSYxE_tH7XcZKavlAJ8ja5bhrVv7M3FYrQCupT7kX4vf1-sFkcAuEB-m9sBI0XSR-o8s\/s16000\/.bat%2520file%2520download%2520payload%2520file%2520%28Source%2520-%2520Point%2520Wild%29.webp?ssl=1\" alt=\".bat file download payload file (Source - Point Wild)\"><figcaption class=\"wp-element-caption\">.bat file download payload file (Source \u2013 Point Wild)<\/figcaption><\/figure>\n<\/div>\n<p>Using GitHub as a delivery channel adds perceived legitimacy, since traffic to the platform rarely triggers network-level alerts.<\/p>\n<p>Once downloaded, the payload executes through PowerShell\u2019s\u00a0<code>Start-Process<\/code>\u00a0command and stores itself as\u00a0<code>msedge_proxy.exe<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgK7F7u_wu45_MhZ08OJhd1KNzGPnqgkVoKXj2J_apeSIhc2UDO5TTQTiIaUgxIDR4DwTym2ouQHjLQcbDCgg1bf6t79qrBrWRdeVNXmNAN44JY8Xcu2UYD0sLYzvtR65j0rsDmDUWMfQFYkIDkJYxqesUjEaTwKOii02t_7oehGZtoGQC-49CyW5KBKuA\/s16000\/Dropped%2520msedge_proxy.exe%2520file%2520%28Source%2520-%2520Point%2520Wild%29.webp?ssl=1\" alt=\"Dropped msedge_proxy.exe file (Source - Point Wild) \"><figcaption class=\"wp-element-caption\">Dropped msedge_proxy.exe file (Source \u2013 Point Wild) <\/figcaption><\/figure>\n<\/div>\n<p>The malware then runs environment checks \u2014 querying the system manufacturer through WMIC, scanning the tasklist for tools like Wireshark, OllyDbg, and x64dbg, and examining registry paths linked to VMware, VirtualBox, and Hyper-V. <\/p>\n<p>It also inspects the Process Environment Block (PEB) for active debuggers and measures timing behavior using\u00a0<code>QueryPerformanceFrequency<\/code>\u00a0to catch emulated environments. <\/p>\n<p>Only when every check passes does the RAT proceed to beacon its C2 server and await operator commands.<\/p>\n<p>Security teams and individuals working within judicial or legal environments should act on the following:<\/p>\n<ul class=\"wp-block-list\">\n<li>Keep <a href=\"https:\/\/cybersecuritynews.com\/understanding-false-positives-in-antivirus-software\/\" id=\"39066\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus software<\/a> updated and ensure real-time protection remains active at all times.<\/li>\n<li>Never open email attachments from unverified senders, especially compressed archive files.<\/li>\n<li>Avoid clicking on suspicious links or downloading files from sources outside official channels.<\/li>\n<li>Monitor running processes in Task Manager regularly and investigate unfamiliar entries like\u00a0<code>msedge_proxy.exe<\/code>.<\/li>\n<li>Do not install cracked or pirated software, as these commonly serve as secondary infection vectors.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/attackers-abuse-court-documents-targets-with-covert-rat\/\">Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/attackers-abuse-court-documents-targets-with-covert-rat\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT A new wave of targeted attacks is quietly hitting Argentina\u2019s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan known as [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11427","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11427"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11427"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11427\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}