Abusing Discord to deliver Agent Tesla malware · Blog · Sublime Security
ID: 9ac29e4f-19a8-58e8-a07f-219e6d163a60
STIX ID: report--9ac29e4f-19a8-58e8-a07f-219e6d163a60
Feed Name: Sublime Security Blog
Sublime's Attack Spotlight details an in-the-wild email phishing sample targeting Google Workspace where a fake purchase order link points to Discord's CDN and auto-downloads a VBE that installs Agent Tesla, a .NET RAT and data stealer commonly used to enable secondary ransomware deployment. The report highlights social-engineering elements (fake PDF/logo), use of high-reputation infrastructure to evade inspection, mismatched headers, and the detection signals that prevented the attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
