logo

CVE-2017-11882 To Deliver Agent Tesla

ID: 00c951dd-afab-5625-8d1e-a80b6e5de680

STIX ID: report--00c951dd-afab-5625-8d1e-a80b6e5de680

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Executive summary: The report documents a phishing-driven malware campaign that abuses vulnerable Microsoft Excel files to download an obfuscated VBS which retrieves a steganographically embedded Base64 DLL from a JPG; the DLL is decoded and loaded via PowerShell, uses RegAsm process injection to deliver the Agent Tesla infostealer, and exfiltrates stolen browser, mail, FTP credentials and keystrokes to a Telegram bot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.