AgentTesla Spreads Via CHM & PDF Files In New Attacks
ID: 308682f0-8723-5638-8294-a37e032544e6
STIX ID: report--308682f0-8723-5638-8294-a37e032544e6
Feed Name: Cyble Blog
Threat Score
This report details active campaigns distributing the AgentTesla information-stealer through Gzip-compressed CHM files and malicious PDFs that execute encoded PowerShell to download a .NET loader DLL which decrypts and injects AgentTesla; the analysis includes the full infection chain, TTPs (PowerShell, DLL loader, process injection, persistence), multiple IOCs (hashes, domains, IP), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
