Agent Tesla Targeting United States & Australia: Revealing the Attackers’ Identities
ID: c0ccc41d-bb16-55c3-ba89-376eeaf6577d
STIX ID: report--c0ccc41d-bb16-55c3-ba89-376eeaf6577d
Feed Name: Check Point Research
Threat Score
Check Point Research documents multiple Agent Tesla campaigns (Nov 2023–Mar 2024) that used socially engineered malspam (ISO/.img attachments) and a .NET obfuscator called Cassandra Protector to deliver an infostealer RAT to US and Australian organizations; the report maps infrastructure (Plesk/RoundCube, RDP/SSH hosts), profiles two criminal actors (‘Bignosa’ and ‘Gods’) with linked social-media footprints, and provides IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
