logo

Agent Tesla Keylogger delivered using cybersquatting

ID: 0f731f0c-de20-5156-96a3-9e302e095589

STIX ID: report--0f731f0c-de20-5156-96a3-9e302e095589

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed an AgentTesla keylogger campaign that used cybersquatting (diodetechs.com) and malicious Office macros to deliver a Windows .NET keylogger (cc.exe, MD5 e4117e6974363cac8b37e5e3ff5d07a6). The report documents infection and persistence mechanisms, modules for keylogging, screenshots, password theft and anti-analysis, C2 communication and data exfiltration formats, and provides IOCs; the malicious domain was suspended after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.