[SANS ISC] Agent Tesla Trojan Abusing Corporate Email Accounts

I published the following diary on isc.sans.edu: “Agent Tesla Trojan Abusing Corporate Email Accounts“: The trojan ‘Agent Tesla’ is not brand new, discovered in 2018, it is written in VisualBasic and has plenty of interesting features. Just have a look at the MITRE ATT&CK overview of its TTP. I found a

[The post [SANS ISC] Agent Tesla Trojan Abusing Corporate Email Accounts has been first published on /dev/random]

Continue reading [SANS ISC] Agent Tesla Trojan Abusing Corporate Email Accounts

Agent Tesla: Evading EDR by Removing API Hooks

Written by Toby Gray and Ratnesh Pandey. Endpoint detection and response (EDR) tools rely on operating system events to detect malicious activity that is generated when malware is run. These events are later correlated and analysed to detect anomalous… Continue reading Agent Tesla: Evading EDR by Removing API Hooks

More AgentTesla keylogger info-stealer campaigns hitting UK

We are still seeing continuous AgentTesla keylogger / Info-Stealer campaigns hitting the UK. We sill aren’t seeing a lot of other malware at the moment. I have received about 20 different versions over the last week that have all been nothing spe… Continue reading More AgentTesla keylogger info-stealer campaigns hitting UK

multiple malware delivered from compromised website run on a domestic BT IP address

As I mentioned earlier in the week, we aren’t seeing massive amounts of malware, especially in the UK at the moment BUT we do see a steady lowish volume stream of commodity malware. These are they standard easy to purchase and use malware tools l… Continue reading multiple malware delivered from compromised website run on a domestic BT IP address

Fake Payment receipt vbs drops njrat bladabindi downloads Agent Tesla via Sendspace.

A rather interesting malware campaign from overnight. It all starts with an email pretending to be a payment receipt that contains a .tar attachment which contains a vbs file. As per usual the email is just generic enough to entice a recipient to open … Continue reading Fake Payment receipt vbs drops njrat bladabindi downloads Agent Tesla via Sendspace.