Targeted COVERT RAT Attacks on Argentina's Judicial Sector Using Court Docs and GitHub Payloads

Targeted COVERT RAT Attacks on Argentina's Judicial Sector Using Court Docs and GitHub Payloads

First seen 18 Mar 2026, 09:13 UTC GbhackersCybersecuritynews 63.5

Article Content

Browse articles
ThreatCluster

A spear-phishing campaign dubbed Operation Covert Access is targeting Argentina's judicial sector with a Rust-based Remote Access Trojan (RAT) known as COVERT RAT. Attackers are leveraging fake court documents to deceive legal professionals into executing malicious payloads. The attack method involves chaining Windows LNK shortcuts, BAT loaders, and PowerShell scripts to download and execute the RAT from GitHub. The stealthy nature of the malware allows it to operate undetected, posing significant risks to sensitive judicial data. This targeted operation highlights vulnerabilities within the judicial system's cybersecurity defenses. The campaign is ongoing, and affected systems include various components of the judicial infrastructure. Specific numbers and CVEs were not disclosed in the articles, but the threat level is considered high due to the targeted nature of the attacks. Legal professionals are advised to exercise caution when handling unexpected court communications.

Key Points: • Operation Covert Access targets Argentina's judicial sector using spear-phishing tactics. • Attackers deploy COVERT RAT via malicious payloads hosted on GitHub. • The campaign exploits fake court documents to lure legal professionals.

Timeline

2026-03-18
Articles published detailing the ongoing Operation Covert Access
Date unknown
Attack method involving LNK shortcuts and PowerShell identified
Date unknown
COVERT RAT discovered in targeted judicial systems