12/16/2021- 6:34 a.m.
‘Iranian hackers’ steal airline data by abusing Slack API
Suspected threat actors from Iran are deploying a newly-discovered backdoor called “Aclip” which reportedly abuses Slack API – an interface that makes covert communication easier.
The hackers targeted an unidentified Asian airline as early as 2019 to steal flight reservation data.
The backdoor collects system information such as hostname, username and external IP address which is then encrypted and exfiltrated.