Alpha Cyber

Info-Stealing Malware Propagated Through Indian Software Products

In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Info-Stealing Malware Propagated Through Indian Software Products

In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches. One such emerging threat is the propagation of info-stealing malware through products developed by an Indian software company. As companies and government agencies worldwide continue to rely on software solutions from global vendors, the risks associated with malicious code embedded in these products are on the rise. In this blog post, we will explore how this particular malware operates, the potential impact on your organization, and the critical infrastructure mapping necessary to protect your network.

Understanding the Threat: How Info-Stealing Malware Propagates

Info-stealing malware, as the name suggests, is designed to steal sensitive information such as login credentials, credit card details, and personal data. What sets this recent wave of attacks apart is its method of propagation. Cybercriminals have strategically targeted an Indian software company, infiltrating their products with malicious code. When organizations install or update software from this vendor, the embedded malware is activated, giving attackers the ability to steal valuable information.

The primary challenge here is the nature of the attack: many organizations might already be using these products unknowingly, making the malware particularly dangerous. This kind of attack typically goes undetected for long periods, with the threat operating silently within a network, stealing sensitive data before it’s even noticed.

The Service Infrastructure Map: How the Attack Unfolds

Indian Firm Spread Trojans

To protect your organization from this attack, it is essential to understand the infrastructure involved in the malware’s propagation. The malware operates through several key stages, often leveraging trusted software update mechanisms or compromised components that are regularly updated.

Here is an overview of the service infrastructure:

Initial Access via Compromised Software: The malware is embedded within legitimate software distributed by an Indian software company. Once installed, it silently runs in the background, waiting to exfiltrate data.

Command-and-Control Communication: Once activated, the malware establishes communication with remote servers, often located on IPs known to be used by cybercriminals.

Data Exfiltration: Once communication is established, the malware collects sensitive data, such as usernames, passwords, and financial information, and sends it back to the cybercriminals.

Persistence Mechanisms: To remain undetected, the malware often includes mechanisms to maintain persistence on the system, ensuring it can continue to collect and exfiltrate data over an extended period.

Table of Indicators of Compromise (IOCs) to Block

The following table lists the key Indicators of Compromise (IOCs) that should be blocked to prevent this attack from compromising your network. By blocking these IOCs, organizations can enhance their detection capabilities and reduce the risk of infection.

TypeIndicator
IP Address5.180.185.42
50.2.191.154
104.140.17.242
MD5 Hasha5d7425a155f113feab8f350f5da5ffd
7cc60842bebea9bb260302f1b17e5dbb
6ceb061081050b252bc7d10493bcc583
a80df401cca7f12bb5bffb04385db6c3
SHA-256 Hash6f49756749d175058f15d5f3c80c8a7d46e80ec3e5eb9fb31f4346abdb72a0e7
bfa99c41aecc814de5b9eb8397a27e516c8b0a4e31edd9ed1304da6c996b4aaa
2eae4f06f2c376c6206c632ac93f4e8c4b3e0e63eca3118e883f8ac479b2f852
4df9b7da9590990230ed2ab9b4c3d399cf770ed7f6c36a8a10285375fd5a292f
SHA-1 Hash33865d7efbb75c69b296e1fc3cfc31f440d7b15d
d5bac4f5440801b6d9d52c3431c5d4f2d568ec1b
8c21f78e8e1ce2b3b1f3f49ec6723bfc44257768
76922473c0778b4d550da93f70bb1c15efb9c6a0

Actionable Steps to Mitigate the Risk

Here are some key actions organizations should take to protect themselves from this type of attack:

Update All Software: Ensure that your organization is using only trusted, up-to-date versions of software. Stay on top of updates from vendors and monitor for unusual changes in software behavior.

Monitor and Block Suspicious IPs: Use network monitoring tools to track and block the IP addresses listed in the IOC table. Regularly scan for anomalous activity coming from these IPs.

Implement Strong Endpoint Security: Ensure that all endpoints are protected by strong security software, including firewalls, anti-malware, and intrusion detection systems.

Educate Employees: Train your workforce to recognize phishing attempts and malicious email attachments that may contain this malware. Awareness can significantly reduce the risk of human error leading to a security breach.

Incident Response Plan: Be prepared to respond swiftly to any signs of compromise. Having a structured and tested incident response plan can help minimize the impact of any breach.

Conclusion

As the digital landscape becomes more interconnected, the threats to our cybersecurity infrastructure are evolving. Info-stealing malware propagated through compromised software presents a serious risk to both individuals and organizations. By taking proactive steps to block IOCs, monitor your network, and ensure your security measures are up to date, you can protect your organization from falling victim to these types of attacks.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]