logo

Hackers Exploiting MS Excel Vulnerability to Spread Agent Tesla Malware

ID: 684da609-7ad2-5a7b-8d2b-8a3d85d7322d

STIX ID: report--684da609-7ad2-5a7b-8d2b-8a3d85d7322d

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2023-12-21

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Zscaler and other researchers observed active phishing campaigns using invoice-themed Excel attachments to exploit CVE-2017-11882 and deliver Agent Tesla via a multi-stage chain that includes an obfuscated VBS downloader, steganographic JPG containing a Base64-encoded DLL, and DLL injection into RegAsm.exe; the report also highlights related phishing and stealer campaigns (RedLine, Vidar) and credential/2FA theft schemes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.