Hackers are targeting Indian government entities and energy companies with the aim of delivering a modified version of the info-stealer malware HackBrowserData. The attackers want to steal sensitive information and sometimes use Slack as a command-and-control (C2).

The malware is distributed via email and appears to be an invitation letter from the Indian Air Force.
"After executing the malware, the attacker used Slack channels as export points to upload confidential internal documents, private email , and saved data browser," said researcher Arda Büyükkaya of EclecticIQ.
See also: Snake info-stealer malware: Distributed via Facebook messages
The HackBrowserData distribution campaign was observed in early March and is codenamed Operation FlightNight.
The targets span multiple government entities in India, including those related to electronic communications, IT governance, and national defense. In addition, attackers have targeted private energy, stealing financial documents, employee personal information , and details about oil and gas drilling activities.
How does the attack work?
As we mentioned earlier, the attack begins with a phishing email, containing an ISO file (“invite.iso”), which, in turn, contains a Windows shortcut (LNK) that triggers the execution of a hidden binary (“scholar.exe”).
Also, a PDF file is displayed, supposedly an invitation letter from the Indian Air Force, while the HackBrowserData malware secretly collects documents and browser data and transmits them to a Slack.
See also: Snake info-stealer malware: Distributed via Facebook messages

What are the best methods for protecting against info-stealer malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
Installing reliable security software is another key method of protecting against info-stealer malware, such as HackBrowserData. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing.
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
See also: MacOS info-stealer malware evades detection by XProtect
Using strong passwords and changing them regularly can protect your data from theft. Also, using a password manager can help manage and secure your passwords.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware (e.g. HackBrowserData malware).
Source: thehackernews.com
