Cybersecuritynews Targeted COVERT RAT Attacks on Argentina's Judicial Sector Using Court Docs and GitHub Payloads
Article Content
- •Operation Covert Access targets Argentina's judicial sector using spear-phishing tactics.
- •Attackers deploy COVERT RAT via malicious payloads hosted on GitHub.
- •The campaign exploits fake court documents to lure legal professionals.
A spear-phishing campaign dubbed Operation Covert Access is targeting Argentina's judicial sector with a Rust-based Remote Access Trojan (RAT) known as COVERT RAT. Attackers are leveraging fake court documents to deceive legal professionals into executing malicious payloads. The attack method involves chaining Windows LNK shortcuts, BAT loaders, and PowerShell scripts to download and execute the RAT from GitHub. The stealthy nature of the malware allows it to operate undetected, posing significant risks to sensitive judicial data. This targeted operation highlights vulnerabilities within the judicial system's cybersecurity defenses. The campaign is ongoing, and affected systems include various components of the judicial infrastructure. Specific numbers and CVEs were not disclosed in the articles, but the threat level is considered high due to the targeted nature of the attacks. Legal professionals are advised to exercise caution when handling unexpected court communications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Covert RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…