logo

Thousands of Australian Businesses Targeted With 'Reliable' Agent Tesla RAT

ID: dabd44d7-1724-5a2f-b748-a556fb14ab71

STIX ID: report--dabd44d7-1724-5a2f-b748-a556fb14ab71

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-04-21

Author: John Leyden, Contributing Writer

...
...

Check Point researchers observed a high-volume phishing campaign that targeted primarily Australian (and some U.S.) businesses by distributing the Agent Tesla RAT via booby-trapped email attachments. Operators using infrastructure hosted with Plesk/RoundCube and delivery obfuscation (Cassandra Protector, converting .NET payloads to ISO/.img) ran mass spam runs from prepared lists (e.g., "AU B2B Lead.txt"); the campaign enabled credential and data theft, showed integration with Telegram/Discord for exfiltration/command, and involved actors tracked as "Bignosa" and "Gods."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.