Indian government entities and energy companies have been targeted by hackers with an aim to deliver a modified version of an open-source information stealer malware called HackBrowserData and collect sensitive information.
Dutch cybersecurity firm EclecticIQ researcher, Arda Büyükkaya, said that the information stealer was delivered via a phishing email, masquerading as an invitation letter from the Indian Air Force.
The attacker utilized Slack channels as exfiltration points to upload confidential internal documents, private email messages, and cached web browser data after the malware’s execution.
The campaign which was discovered in early March was codenamed Operation FlightNight in reference to the Slack channels operated by the adversary.
Targets of the malicious activity include multiple government entities in India, and those related to electronic communications, IT governance, and national defense.
The threat actor is said to have successfully compromised private energy companies, harvesting financial documents, personal details of employees, details about drilling activities in oil and gas. Around 8.81 GB of data has been exfiltrated over the course of the campaign.
The attack chain starts with a phishing message containing an ISO file (“invite.iso”), which, in turn, contains a Windows shortcut (LNK) that triggers the execution of a hidden binary (“scholar.exe”) present within the mounted optical disk image.
Simultaneously, a lure PDF file that claims to be an invitation letter from the Indian Air Force is displayed to the victim while the malware secretly harvests documents and cached web browser data and transmits them to an actor-controlled Slack channel named FlightNight.
Researchers suggest that the original PDF file was very likely stolen during a previous intrusion and was repurposed by the attackers.
The malware is an altered version of HackBrowserData that goes beyond its browser data theft features to incorporate capabilities to siphon documents (Microsoft Office, PDFs, and SQL database files), communicate over Slack, and better evade detection using obfuscation techniques.
Although the hacker group behind this campaign wasn’t identified, the similarities in the malware and the delivery technique’s metadata indicate a connection with an attack reported earlier in January when cybercriminals targeted Indian Air Force officials with a credential stealer malware called GoStealer.
According to EclecticIQ, both campaigns are likely the work of the same threat actor targeting Indian government entities.
The researcher added that the Operation FlightNight and the Go-Stealer campaign highlight a simple yet effective approach by threat actors to use open-source tools for cyber espionage.
Image Credits : TechCrunch

















Comments