FortiGuard Labs breaks down a multi-stage Agent Tesla campaign targeting Windows users. The infection chain starts with a business-themed phishing email containing a RAR attachment with a JScript loader (.jse). The loader fetches an encrypted PowerShell script from catbox.moe, which then performs process hollowing against the legitimate aspnet_compiler.exe to inject the Agent Tesla payload entirely in memory. Anti-analysis checks probe for VMware, VirtualBox, and Hyper-V environments before proceeding to credential harvesting — extracting browser cookies and stored passwords — and exfiltrating data via SMTP. IOCs, MITRE ATT&CK TTPs, and Fortinet product detections are provided.
1 Impression