Threat Advisory

Unveiling a Strategic Go Stealer Variant with Browser Targeting and Slack Data Exfiltration

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researcher has uncovered a targeted cyber threat potentially aimed at the Indian Air Force. The campaign employs a Go Stealer variant distributed through a deceptive ZIP file named "SU-30_Aircraft_Procurement," hosted on the anonymous file storage platform Oshi. The timing of the attack coincides with the Indian Defense Ministry's approval of the procurement of 12 Su-30 MKI fighter jets in September 2023. The threat actor strategically exploits this development to target Indian Air Force professionals, utilizing a sequence of infection involving a ZIP file, an ISO file, an .lnk file, and ultimately deploying the stealer payload.[/subscribe_to_unlock_form]

Summary:

Researcher has uncovered a targeted cyber threat potentially aimed at the Indian Air Force. The campaign employs a Go Stealer variant distributed through a deceptive ZIP file named "SU-30_Aircraft_Procurement," hosted on the anonymous file storage platform Oshi. The timing of the attack coincides with the Indian Defense Ministry's approval of the procurement of 12 Su-30 MKI fighter jets in September 2023. The threat actor strategically exploits this development to target Indian Air Force professionals, utilizing a sequence of infection involving a ZIP file, an ISO file, an .lnk file, and ultimately deploying the stealer payload.[emaillocker id="1283"]

The Go Stealer variant, identified by researcher, is an evolved form of an open source Go Stealer available on GitHub. This variant, however, distinguishes itself with additional features such as an expanded capability to target multiple browsers and the ability to exfiltrate data using Slack. The attack begins with a malicious link, leading to the download of the ZIP file. The subsequent infection chain involves mounting an ISO file, executing a .lnk file, and deploying the stealer payload. The stealer, coded in Go, specifically targets Google Chrome, Edge, and Brave browsers, extracting login credentials and cookies. This variant introduces a novel tactic of using the Slack API for data exfiltration, taking advantage of the platform's common use in enterprise networks.

The identified Go Stealer variant poses a significant threat to Indian Defense Personnel, with its specific targeting of sensitive information from the Indian Air Force. The campaign's timing, aligned with the procurement announcement, suggests potential espionage or targeted attacks. Unlike conventional stealers, this malware demonstrates a more focused approach, selectively harvesting login credentials and cookies from specific browsers. The advanced features, including expanded browser targeting and data exfiltration via Slack, emphasize the threat actor's intent to gather precise information. Researcher recommends vigilance in downloading files only from trusted sources, deploying robust antivirus solutions, strengthening system security with strong passwords and two-factor authentication, regular data backups, and awareness of evolving cyber threats to mitigate the risk of such targeted attacks.

Threat Profile:

 

References:

The following reports contain further technical details:

https://cyble.com/blog/cyber-espionage-attack-on-the-indian-air-force-go-based-infostealer-exploits-slack-for-data-theft/

[/emaillocker]
crossmenu