Cyberwarfare

Cyberespionage Campaign Targets Government, Energy Entities in India

Threat intelligence firm EclecticIQ documents the delivery of malware phishing lures to government and private energy organizations in India.

Threat intelligence firm EclecticIQ documents the delivery of malware phishing lures to government and private energy organizations in India.

Multiple government entities and private energy organizations in India have been targeted in a cyberespionage campaign that uses an open source information stealer for data exfiltration, according to a warning from threat intelligence firm EclecticIQ.

As part of the campaign, tagged to as Operation FlightNight, phishing lures masquerading as an invitation letter from the Indian Air Force were sent to various Indian government entities, including agencies for electronic communications, IT governance, and national defense.

The phishing emails carried an ISO file containing the malware and a shortcut file (LNK) posing as the PDF invitation letter. Once opened, it executed the hidden malware, while displaying a decoy document that was likely stolen in a previous intrusion and repurposed.

Immediately after execution, the malware, a modified version of the open source information stealer HackBrowserData, started exfiltrating documents and web browser data from the victim’s machine, including login credentials, cookies, and browsing history.

The same threat actor was also seen targeting Indian energy companies to steal financial documents, employee information, and data about drilling activities in oil and gas.

“In total, the actor exfiltrated 8,81 GB of data, leading analysts to assess with medium confidence that the data could aid further intrusions into the Indian government’s infrastructure,” EclecticIQ noted.

Advertisement. Scroll to continue reading.

The attackers modified the HackBrowserData stealer to implement communication over Slack channels, obfuscation, and functionality to exfiltrate Office documents, PDF files, and SQL database files. All harvested data is exfiltrated via attacker-operated Slack channels named FlightNight.

EclecticIQ has found similarities between Operation FlightNight and a GoStealer campaign documented in January 2024 that targeted Indian Air Force officials with an information stealer written in Golang.

“Operation FlightNight and the Go-Stealer campaign highlight a simple yet effective approach by threat actors to use open-source tools for cyber espionage. This underscores the evolving landscape of cyber threats, wherein actors abuse widely used open-source offensive tools and platforms to achieve their objectives with minimal risk of detection and investment,” EclecticIQ added.

Related: Data of 750 Million Indian Mobile Subscribers Sold on Hacker Forums

Related: Stealthy Cyberespionage Campaign Remained Undiscovered for Two Years

Related: Chinese Cyberspies Targeting ASEAN Entities

Related Content

Phishing

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Phishing

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or...

Cybercrime

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Mobile & Wireless

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Cyberwarfare

Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version