Info-Stealing Malware Propagated Through Indian Software Products
In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches.

In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches. One such emerging threat is the propagation of info-stealing malware through products developed by an Indian software company. As companies and government agencies worldwide continue to rely on software solutions from global vendors, the risks associated with malicious code embedded in these products are on the rise. In this blog post, we will explore how this particular malware operates, the potential impact on your organization, and the critical infrastructure mapping necessary to protect your network.
Understanding the Threat: How Info-Stealing Malware Propagates
Info-stealing malware, as the name suggests, is designed to steal sensitive information such as login credentials, credit card details, and personal data. What sets this recent wave of attacks apart is its method of propagation. Cybercriminals have strategically targeted an Indian software company, infiltrating their products with malicious code. When organizations install or update software from this vendor, the embedded malware is activated, giving attackers the ability to steal valuable information.
The primary challenge here is the nature of the attack: many organizations might already be using these products unknowingly, making the malware particularly dangerous. This kind of attack typically goes undetected for long periods, with the threat operating silently within a network, stealing sensitive data before it’s even noticed.
The Service Infrastructure Map: How the Attack Unfolds

To protect your organization from this attack, it is essential to understand the infrastructure involved in the malware’s propagation. The malware operates through several key stages, often leveraging trusted software update mechanisms or compromised components that are regularly updated.
Here is an overview of the service infrastructure:
Initial Access via Compromised Software: The malware is embedded within legitimate software distributed by an Indian software company. Once installed, it silently runs in the background, waiting to exfiltrate data.
Command-and-Control Communication: Once activated, the malware establishes communication with remote servers, often located on IPs known to be used by cybercriminals.
Data Exfiltration: Once communication is established, the malware collects sensitive data, such as usernames, passwords, and financial information, and sends it back to the cybercriminals.
Persistence Mechanisms: To remain undetected, the malware often includes mechanisms to maintain persistence on the system, ensuring it can continue to collect and exfiltrate data over an extended period.
Table of Indicators of Compromise (IOCs) to Block
The following table lists the key Indicators of Compromise (IOCs) that should be blocked to prevent this attack from compromising your network. By blocking these IOCs, organizations can enhance their detection capabilities and reduce the risk of infection.
| Type | Indicator |
|---|---|
| IP Address | 5.180.185.42 |
| 50.2.191.154 | |
| 104.140.17.242 | |
| MD5 Hash | a5d7425a155f113feab8f350f5da5ffd |
| 7cc60842bebea9bb260302f1b17e5dbb | |
| 6ceb061081050b252bc7d10493bcc583 | |
| a80df401cca7f12bb5bffb04385db6c3 | |
| SHA-256 Hash | 6f49756749d175058f15d5f3c80c8a7d46e80ec3e5eb9fb31f4346abdb72a0e7 |
| bfa99c41aecc814de5b9eb8397a27e516c8b0a4e31edd9ed1304da6c996b4aaa | |
| 2eae4f06f2c376c6206c632ac93f4e8c4b3e0e63eca3118e883f8ac479b2f852 | |
| 4df9b7da9590990230ed2ab9b4c3d399cf770ed7f6c36a8a10285375fd5a292f | |
| SHA-1 Hash | 33865d7efbb75c69b296e1fc3cfc31f440d7b15d |
| d5bac4f5440801b6d9d52c3431c5d4f2d568ec1b | |
| 8c21f78e8e1ce2b3b1f3f49ec6723bfc44257768 | |
| 76922473c0778b4d550da93f70bb1c15efb9c6a0 |
Actionable Steps to Mitigate the Risk
Here are some key actions organizations should take to protect themselves from this type of attack:
Update All Software: Ensure that your organization is using only trusted, up-to-date versions of software. Stay on top of updates from vendors and monitor for unusual changes in software behavior.
Monitor and Block Suspicious IPs: Use network monitoring tools to track and block the IP addresses listed in the IOC table. Regularly scan for anomalous activity coming from these IPs.
Implement Strong Endpoint Security: Ensure that all endpoints are protected by strong security software, including firewalls, anti-malware, and intrusion detection systems.
Educate Employees: Train your workforce to recognize phishing attempts and malicious email attachments that may contain this malware. Awareness can significantly reduce the risk of human error leading to a security breach.
Incident Response Plan: Be prepared to respond swiftly to any signs of compromise. Having a structured and tested incident response plan can help minimize the impact of any breach.
Conclusion
As the digital landscape becomes more interconnected, the threats to our cybersecurity infrastructure are evolving. Info-stealing malware propagated through compromised software presents a serious risk to both individuals and organizations. By taking proactive steps to block IOCs, monitor your network, and ensure your security measures are up to date, you can protect your organization from falling victim to these types of attacks.



