logo

Operation FlightNight: Indian Government Entities and Energy Sector Targeted by Cyber Espionage Campaign

ID: 1c09a4ab-e6c9-5e97-89d1-29eac2023018

STIX ID: report--1c09a4ab-e6c9-5e97-89d1-29eac2023018

Feed Name: EclecticIQ

Threat Score
78/100

Date Published: 2024-03-27

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

Operation FlightNight is a targeted cyber-espionage campaign observed from March 2024 that leveraged a modified HackBrowserData information stealer delivered via ISO files and LNK shortcuts masquerading as an Indian Air Force invitation; the malware collected browser credentials, cached data and selected document types and exfiltrated approximately 8.81 GB of sensitive files to attacker-operated Slack channels. The report includes malware analysis details, overlapping indicators with a prior Go-Stealer incident, hardcoded Slack tokens and workspaces, SHA-256 hashes, MITRE TTP mappings, detection signals (e.g., ISO mount events, LNK execution), and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.