AgentTesla Malware Targets Users Via Malicious Control Panel
ID: 7758e9e4-d5a1-50e3-a9c6-c8e51f6eb934
STIX ID: report--7758e9e4-d5a1-50e3-a9c6-c8e51f6eb934
Feed Name: Cyble Blog
Cyble CRIL analyzed a multi-stage AgentTesla information-stealing campaign that distributes via phishing emails containing a malicious .cpl control-panel file; the CPL executes obfuscated PowerShell which downloads a .NET loader and injects AgentTesla into system processes (RegSvcs.exe, Msbuild.exe). The campaign implements persistence (Startup folder and scheduled tasks), defense-evasion (AMSI and Windows Defender disabling, exclusions), and provides extensive IOCs (file hashes, malicious URL) and a YARA signature for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
