Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Agent Tesla Phishing Campaign Evades Detection with Advanced Tactics

Agent Tesla Phishing Campaign Evades Detection with Advanced Tactics

Posted on February 26, 2026 By CWS

A sophisticated phishing campaign has recently been uncovered, delivering the notorious Agent Tesla malware through a cleverly designed multi-phase attack that leaves minimal traces on targeted systems. Leveraging business-themed phishing emails and advanced evasion techniques, this campaign underscores the evolving threat posed by commercially available malware in the hands of adept cybercriminals.

Phishing Tactics and Malware Delivery

The attackers are utilizing emails that mimic business communications, embedding obfuscated scripts and executing them directly in memory to extract sensitive information from Windows users. This approach allows the malware to bypass many security tools, highlighting the danger of commercially available malware when utilized by skilled individuals.

Agent Tesla, a malware-as-a-service offering, has been a favorite among cybercriminals since its emergence in 2014. Its ability to steal browser credentials, track keystrokes, and access email account details makes it a formidable tool. Despite being well-known, its delivery mechanisms continue to evolve, keeping it one step ahead of traditional security measures.

Complex Attack Chain and Evasion Techniques

Researchers from Fortinet have documented this campaign, pointing out that the true threat lies not in the malware itself, but in the sophisticated delivery pipeline crafted to deploy it. The attack chain is meticulously designed to evade detection at multiple stages, from the initial phishing email to the final payload executing entirely in memory.

The operation begins with a phishing email masquerading as a business inquiry, featuring subject lines such as “New Purchase Order PO0172.” The email includes a RAR file attachment containing an obfuscated JScript Encoded file. This method circumvents email filters that typically block executable files, allowing the attack to proceed automatically once the attachment is opened by the user.

Memory-Only Execution and Anti-Analysis Measures

A standout feature of this attack is its ability to transition from a simple script to an active payload without writing anything to the disk. The JSE file fetches an encrypted PowerShell script from catbox[.]moe, which uses a custom AES-CBC decryption routine to decrypt subsequent stages directly in memory.

The PowerShell script then performs process hollowing on the aspnet_compiler.exe process, injecting the Agent Tesla payload into it. This tactic, combined with anti-analysis measures like checking for virtual environments and specific DLL files, ensures the malware remains undetected by traditional security solutions.

To counter such threats, security teams should block script-based email attachments and enforce PowerShell execution policies. Tools capable of detecting memory-based injection and process hollowing are crucial, as is monitoring outbound SMTP traffic for signs of data exfiltration. Regular employee training on phishing awareness remains a vital defense against such social engineering attacks.

Cyber Security News Tags:Agent Tesla, anti-analysis, Cybersecurity, email security, endpoint protection, in-memory execution, Malware, malware-as-a-service, Phishing, process hollowing, Windows security

Post navigation

Previous Post: Cloaking Platform 1Campaign Bypasses Google Ads Security
Next Post: Wireshark 4.6.4 Update Enhances Security and Stability

Related Posts

New HTTP Smuggling Attack Technique Let Hackers Inject Malicious Requests New HTTP Smuggling Attack Technique Let Hackers Inject Malicious Requests Cyber Security News
SpyCloud Launches Supply Chain Identity Protection SpyCloud Launches Supply Chain Identity Protection Cyber Security News
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers Cyber Security News
Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data Cyber Security News
Windows Snipping Tool Flaw Exposes User Credentials Windows Snipping Tool Flaw Exposes User Credentials Cyber Security News
Chinese PlushDaemon Hackers use EdgeStepper Tool to Hijack Legitimate Updates and Redirect to Malicious Servers Chinese PlushDaemon Hackers use EdgeStepper Tool to Hijack Legitimate Updates and Redirect to Malicious Servers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark