‘Iranian hackers’ steal airline data by abusing Slack API

0
IMG_20211216_063340_026
Share

12/16/2021- 6:34 a.m.

‘Iranian hackers’ steal airline data by abusing Slack API

Suspected threat actors from Iran are deploying a newly-discovered backdoor called “Aclip” which reportedly abuses Slack API – an interface that makes covert communication easier.

The hackers targeted an unidentified Asian airline as early as 2019 to steal flight reservation data.

The backdoor collects system information such as hostname, username and external IP address which is then encrypted and exfiltrated.

Leave a Reply

Your email address will not be published. Required fields are marked *