Threat Advisory

Cyber Criminals Using Quantum Builder Sold on Dark Web to Deliver Agent Tesla Malware

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A tool named Quantum Builder sold on the dark web that allows cybercriminals to build malicious shortcuts for delivering malware is being used in a campaign pushing a long-time .NET keylogger and remote access trojan named Agent Tesla. Quantum Builder is available for about $200 for two months of access and $950 for lifetime access, it can generate LNK, HTA, and ISO payloads. In this case, the attack chain starts with a spear-phishing mail made up of a GZIP archive attachment that consists of a shortcut designed to execute a PowerShell code that further installs agent tesla malware.[/subscribe_to_unlock_form]

Summary:

A tool named Quantum Builder sold on the dark web that allows cybercriminals to build malicious shortcuts for delivering malware is being used in a campaign pushing a long-time .NET keylogger and remote access trojan named Agent Tesla. Quantum Builder is available for about $200 for two months of access and $950 for lifetime access, it can generate LNK, HTA, and ISO payloads. In this case, the attack chain starts with a spear-phishing mail made up of a GZIP archive attachment that consists of a shortcut designed to execute a PowerShell code that further installs agent tesla malware.[emaillocker id="1283"]

References:

The following reports contain further technical details:

https://thehackernews.com/2022/09/cyber-criminals-using-quantum-builder.html

(Kindly exclude this link in the advisory mail)

https://www.zscaler.com/blogs/security-research/agent-tesla-rat-delivered-quantum-builder-new-ttps

[/emaillocker]
crossmenu