Alert: New Phishing Attack Delivers Keylogger Disguised as Bank Payment Notice
ID: d3b7fa50-5bce-5890-93cd-c7de26bd4ceb
STIX ID: report--d3b7fa50-5bce-5890-93cd-c7de26bd4ceb
Feed Name: The Hacker News
Trustwave SpiderLabs reported a phishing campaign (March 2024) that delivered Agent Tesla via a novel .NET loader hidden in an archive attachment; the loader uses polymorphic decryption, AMSI patching to bypass detection, retrieves an XOR-encoded payload from remote servers, and executes Agent Tesla in memory to stealthily exfiltrate data via SMTP using a compromised legitimate account. The article also references related phishing activity by TA544 (distributing WikiLoader/Remcos), and the widespread Tycoon 2FA-phishing kit, indicating evolving and actively exploited phishing and loader techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
