HomeSecurityHackers use Slack API to steal "airline data"

Hackers use Slack API to steal “airline data”

A suspected Iranian state-backed threat actor is developing a new backdoor called “Aclip” that abuses the Slack API for secret communications.

The threat actor's activity began in 2019 and targeted an unnamed Asian airline to steal flight booking data.

According to a report by IBM Security X-Force, the threat actor is likely the ITG17 group, also known as “MuddyWater,” a very active hacking group that targets organizations around the world.

See also: Hackers steal Microsoft Exchange credentials using IIS module

Slack API hacker data

Slack abuse

Slack is an ideal platform for hiding malicious communications, as the data can blend well with normal business traffic due to its widespread deployment in the enterprise.

This type of abuse is a tactic that other hackers have used in the past, so it's not a new trick. Also, Slack isn't the only legitimate messaging platform being abused to secretly transmit data and commands.

In this case, the Slack API is used by the Aclip backdoor to send system information, files, and screenshots to the C2, while in return it receives commands.

IBM researchers identified the threat actors abusing this communication channel in March 2021 and notified Slack.

See also: Hackers are randomly infecting WordPress plugins to steal credit cards

Slack issued the following public statement in response:

“As described in this post, IBM X-Force has discovered and is actively monitoring a third party attempting to deploy targeted malware by leveraging free workspaces on Slack. As part of X-Force’s investigation, we were made aware of free workspaces being used in this manner.

We investigated and immediately “shut down” the reported Slack Workspaces as a violation of our terms of service. We have confirmed that Slack was not compromised in any way as part of this incident and that no Slack customer data was exposed or compromised. We are committed to preventing misuse of our platform and take action against anyone who violates our terms of service.

Slack encourages people to be vigilant and use basic security measures, including using two-factor authentication, ensuring that computer software and anti-virus software are up to date, creating new and unique passwords for each service they use, and being cautious when interacting with people they don’t know.” – Slack.

data hacker

The Aclip backdoor

Aclip is a recently observed backdoor that runs via a Windows script named 'aclip.bat', hence the name.

The backdoor establishes persistence on an infected device by adding a registry key and is automatically launched at system startup.

Aclip receives PowerShell commands from the C2 server via Slack API functions and can be used to execute further commands, send screenshots of the active Windows desktop, and export files.

hacker

Upon first execution, the backdoor collects basic system information, including hostname, username, and external IP address. This data is Base64 encrypted and passed to the threat actor.

From there, the command execution query phase begins, with Aclip connecting to a different channel in the hacker-controlled Slack workspace.

See also: Hackers send SMS pretending to be from the Iranian government

Screenshots are taken using the PowerShell graphics library and are stored in %TEMP% until exported. Once the images are uploaded to C2, they are deleted.

IBM linked the attack to the MuddyWaters/ITG17 group after its research found two samples of custom malware known to be attributed to this hacking group.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS