Thursday, September 10, 2026

Spear-Phishing Campaign Abuses Argentine Federal Court Rulings to Deliver Covert RAT

Seqrite Labs has uncovered a sophisticated spear-phishing campaign targeting Argentina’s judicial sector with a multi-stage infection chain designed to deploy a stealthy Rust-based Remote Access Trojan (RAT).

The campaign primarily targets Argentina’s judicial institutions, legal professionals, justice-adjacent government bodies, and academic legal organizations.

Attackers abuse legitimate Argentine federal court rulings specifically, preventive detention review documents to establish credibility and facilitate successful malware delivery.

The initial vector leverages targeted spear-phishing emails containing a weaponized ZIP archive with three components: a malicious LNK file (info/juicio-grunt-posting.pdf.lnk), a BAT-based loader script (info/health-check.bat), and an authentic-looking judicial PDF decoy (info/notas.pdf).

The operation, named Operation Covert Access, demonstrates advanced social engineering tactics combined with robust anti-analysis mechanisms to achieve persistent access within judicial institutions and legal organizations across South America.


Infection Chain (Source - Seqrite Labs).
Infection Chain (Source – Seqrite Labs).

When users interact with the LNK file, the execution chain initiates silently while displaying the decoy document to the victim, enabling stealthy payload deployment without triggering suspicion.

Decoy Document Analysis

The decoy document is a legitimate-appearing Argentine federal court resolution written in formal legal Spanish, purporting to originate from the Poder Judicial de la Nación and referencing the real Tribunal Oral en lo Criminal y Correccional N° 2 de la Capital Federal.

It discusses judicial review of preventive detention with conditional release provisions, complete with case numbering, judicial signatures, and procedural language citing specific articles of the Argentine Criminal Procedure Code.

The document’s structure, terminology, and formatting closely mirror authentic court rulings, significantly increasing credibility among legal professionals and substantially increasing the likelihood of user interaction.

Stage 1 involves the LNK file executing PowerShell from the system directory with execution policy bypass and hidden window mode. The shortcut contains a PDF icon disguising the malicious shortcut as a legitimate document. 

Stage 2 features the BAT loader establishing connections to GitHub-hosted repositories to retrieve the second-stage payload.

The PowerShell command uses spoofed User-Agent strings and saves the downloaded executable (health-check.exe) as msedge_proxy.exe within the Microsoft Edge user data directory to appear legitimate.

Stage 3 deploys msedge_proxy.exe, the primary RAT component, which performs extensive anti-analysis checks including VM detection (VMware, VirtualBox, Hyper-V, QEMU, Xen, Parallels), sandbox environment detection, and debugger identification through PEB checks and timing-based analysis.

Anti-Debugging: PEB Checks (source - Seqrite Labs).
Anti-Debugging: PEB Checks (source – Seqrite Labs).

The RAT collects system information, including hostname, username, OS name, and privilege levels, then establishes C2 communication using fallback mechanisms supporting both IPv4 and IPv6, defaulting to 181.231.253.69:4444.

Command and Control Capabilities

The malware advertises a comprehensive command set including PERSIST for persistence installation, DOWNLOAD and UPLOAD for file operations, HARVEST for credential theft, ENCRYPT and DECRYPT for ransomware functionality, and ELEVATE for privilege escalation.

All commands arrive Base64-encoded, with the RAT supporting modular post-exploitation capabilities including DLL-based ransomware, stealer modules, and complete persistence lifecycle management.

The RAT implements multiple persistence techniques through registry Run keys using randomized legitimate-looking value names (SecurityHealthSystray, MicrosoftEdgeAutoLaunch, Teams Machine Installer) and scheduled tasks via schtasks with elevated privileges.

A dedicated PERSIST_REMOVE command enables complete cleanup capability, deleting all registry entries and scheduled tasks upon operator command.

Operation Covert Access demonstrates the continued effectiveness of socially engineered intrusion chains targeting high-trust institutional environments.

Organizations should implement enhanced email filtering for spoofed legal documents, disable LNK file execution from email sources, enforce PowerShell execution policies, and deploy endpoint detection and response solutions capable of identifying suspicious process chains and C2 communications patterns.

IOCs

HashName / File PathC2 Server
dc802b8c117a48520a01c98c6c9587b5info/juicio-grunt-posting.pdf.lnk
45f2a677b3bf994a8f771e611bb29f4fD:\auto_black_abuse\resources\unzipped\20251215_140518_2025-11-28\13adde53bd767d17108786bcc1bc0707c2411a40f11d67dfa9ba1a2c62cc5cf3.zip
02f85c386f67fac09629ebe5684f7fa0info/health-check.bat
976b6fce10456f0be6409ff724d7933b\msedge_proxy.exe
233a9dbcfe4ae348c0c7f4c2defd1ea5info/notas.pdf
——181.231.253.69:4444

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News