logo

Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection

ID: 1e68dd73-cc7e-5103-b249-3cba72a1ecef

STIX ID: report--1e68dd73-cc7e-5103-b249-3cba72a1ecef

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A business-themed phishing campaign distributes Agent Tesla by sending RAR attachments containing obfuscated .jse scripts which download an encrypted PowerShell stage from catbox.moe; the stages perform in-memory AES decryption, process hollowing of aspnet_compiler.exe to load a .NET Agent Tesla payload, perform anti-analysis checks, and exfiltrate harvested credentials via SMTP to mail.taikei-rmc-co.biz. The chain is designed to avoid disk writes and signature-based detections, emphasizing blocking script attachments, enforcing PowerShell restrictions, and monitoring outbound SMTP as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.