Hackers Exploiting MS Excel Vulnerability to Spread Agent Tesla Malware
ID: 684da609-7ad2-5a7b-8d2b-8a3d85d7322d
STIX ID: report--684da609-7ad2-5a7b-8d2b-8a3d85d7322d
Feed Name: The Hacker News
Threat Score
Zscaler and other researchers observed active phishing campaigns using invoice-themed Excel attachments to exploit CVE-2017-11882 and deliver Agent Tesla via a multi-stage chain that includes an obfuscated VBS downloader, steganographic JPG containing a Base64-encoded DLL, and DLL injection into RegAsm.exe; the report also highlights related phishing and stealer campaigns (RedLine, Vidar) and credential/2FA theft schemes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
