Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection
ID: 1e68dd73-cc7e-5103-b249-3cba72a1ecef
STIX ID: report--1e68dd73-cc7e-5103-b249-3cba72a1ecef
Feed Name: cybersecurityNews.com
A business-themed phishing campaign distributes Agent Tesla by sending RAR attachments containing obfuscated .jse scripts which download an encrypted PowerShell stage from catbox.moe; the stages perform in-memory AES decryption, process hollowing of aspnet_compiler.exe to load a .NET Agent Tesla payload, perform anti-analysis checks, and exfiltrate harvested credentials via SMTP to mail.taikei-rmc-co.biz. The chain is designed to avoid disk writes and signature-based detections, emphasizing blocking script attachments, enforcing PowerShell restrictions, and monitoring outbound SMTP as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
