logo

Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection

ID: 41b58e84-b3ce-5466-b044-cce925b93f26

STIX ID: report--41b58e84-b3ce-5466-b044-cce925b93f26

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report describes a phishing‑led Agent Tesla campaign that uses a RAR‑attached JScript loader to fetch AES‑encrypted PowerShell, performs in‑memory decryption and process hollowing into aspnet_compiler.exe, applies anti‑analysis checks, and harvests credentials and system data for exfiltration via attacker SMTP servers, illustrating advanced fileless and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.