logo

Agent Tesla’s Unique Approach: VBS and Steganography for Delivery and Intrusion

ID: 4669257a-75da-5e27-bfe2-08bb3b0a6379

STIX ID: report--4669257a-75da-5e27-bfe2-08bb3b0a6379

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2023-09-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

Agent Tesla was delivered via a VBS that runs obfuscated PowerShell to download an image containing steganographically hidden base64 data; this decodes to a .NET DLL that fetches and decodes a final payload, performs process injection into the legitimate RegAsm.exe process, and steals browser and mail-client data for exfiltration via SMTP. The analysis includes IoCs (file hashes and C2 URL/IP), detailed API-level injection steps, and notes on obfuscation and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.