Summary:
A tool named Quantum Builder sold on the dark web that allows cybercriminals to build malicious shortcuts for delivering malware is being used in a campaign pushing a long-time .NET keylogger and remote access trojan named Agent Tesla. Quantum Builder is available for about $200 for two months of access and $950 for lifetime access, it can generate LNK, HTA, and ISO payloads. In this case, the attack chain starts with a spear-phishing mail made up of a GZIP archive attachment that consists of a shortcut designed to execute a PowerShell code that further installs agent tesla malware.[/subscribe_to_unlock_form]
Summary:
A tool named Quantum Builder sold on the dark web that allows cybercriminals to build malicious shortcuts for delivering malware is being used in a campaign pushing a long-time .NET keylogger and remote access trojan named Agent Tesla. Quantum Builder is available for about $200 for two months of access and $950 for lifetime access, it can generate LNK, HTA, and ISO payloads. In this case, the attack chain starts with a spear-phishing mail made up of a GZIP archive attachment that consists of a shortcut designed to execute a PowerShell code that further installs agent tesla malware.[emaillocker id="1283"]

References:
The following reports contain further technical details:
https://thehackernews.com/2022/09/cyber-criminals-using-quantum-builder.html
(Kindly exclude this link in the advisory mail)
https://www.zscaler.com/blogs/security-research/agent-tesla-rat-delivered-quantum-builder-new-ttps
[/emaillocker]