Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection
ID: 41b58e84-b3ce-5466-b044-cce925b93f26
STIX ID: report--41b58e84-b3ce-5466-b044-cce925b93f26
Feed Name: GBHackers
Threat Score
This report describes a phishing‑led Agent Tesla campaign that uses a RAR‑attached JScript loader to fetch AES‑encrypted PowerShell, performs in‑memory decryption and process hollowing into aspnet_compiler.exe, applies anti‑analysis checks, and harvests credentials and system data for exfiltration via attacker SMTP servers, illustrating advanced fileless and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
