Inside the Stealthy Agent Tesla Infection Chain
ID: 935d0c67-c401-5079-80cc-87eca495665b
STIX ID: report--935d0c67-c401-5079-80cc-87eca495665b
Feed Name: securityonline.info
This report details a sophisticated Agent Tesla infostealer campaign that uses phishing archives and heavily obfuscated batch/PowerShell loaders to execute fileless, in-memory payloads, perform process hollowing and inject a VB.NET payload equipped with anti-debugging, anti-sandbox, and anti-VM checks; once established it steals browser credentials, cookies, keylogs and screenshots and exfiltrates data via common protocols, with recommended defenses including EDR capable of detecting process hollowing and comprehensive phishing awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
