Skip to content
Targeted COVERT RAT Attacks on Argentina's Judicial Sector Using Court Docs and GitHub Payloads

Targeted COVERT RAT Attacks on Argentina's Judicial Sector Using Court Docs and GitHub Payloads

First seen 18 Mar 2026, 09:13 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 19, 2026 at 09:13 UTC

A spear-phishing campaign dubbed Operation Covert Access is targeting Argentina's judicial sector with a Rust-based Remote Access Trojan (RAT) known as COVERT RAT. Attackers are leveraging fake court documents to deceive legal professionals into executing malicious payloads. The attack method involves chaining Windows LNK shortcuts, BAT loaders, and PowerShell scripts to download and execute the RAT from GitHub. The stealthy nature of the malware allows it to operate undetected, posing significant risks to sensitive judicial data. This targeted operation highlights vulnerabilities within the judicial system's cybersecurity defenses. The campaign is ongoing, and affected systems include various components of the judicial infrastructure. Specific numbers and CVEs were not disclosed in the articles, but the threat level is considered high due to the targeted nature of the attacks. Legal professionals are advised to exercise caution when handling unexpected court communications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 205d ago How this analysis works

Timeline

2026-03-18
Articles published detailing the ongoing Operation Covert Access
Date unknown
Attack method involving LNK shortcuts and PowerShell identified
Date unknown
COVERT RAT discovered in targeted judicial systems

More articles in this cluster (2)

Following this threat?

Track Covert RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed