logo

AgentTesla Spreads Via CHM & PDF Files In New Attacks

ID: 308682f0-8723-5638-8294-a37e032544e6

STIX ID: report--308682f0-8723-5638-8294-a37e032544e6

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

This report details active campaigns distributing the AgentTesla information-stealer through Gzip-compressed CHM files and malicious PDFs that execute encoded PowerShell to download a .NET loader DLL which decrypts and injects AgentTesla; the analysis includes the full infection chain, TTPs (PowerShell, DLL loader, process injection, persistence), multiple IOCs (hashes, domains, IP), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.