logo

Abusing Discord to deliver Agent Tesla malware · Blog · Sublime Security

ID: 9ac29e4f-19a8-58e8-a07f-219e6d163a60

STIX ID: report--9ac29e4f-19a8-58e8-a07f-219e6d163a60

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime's Attack Spotlight details an in-the-wild email phishing sample targeting Google Workspace where a fake purchase order link points to Discord's CDN and auto-downloads a VBE that installs Agent Tesla, a .NET RAT and data stealer commonly used to enable secondary ransomware deployment. The report highlights social-engineering elements (fake PDF/logo), use of high-reputation infrastructure to evade inspection, mismatched headers, and the detection signals that prevented the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.