Threat Advisory

Agent Tesla’s Unique Approach: VBS and Steganography for Delivery and Intrusion

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Agent Tesla is a sophisticated Remote Access Trojan (RAT) and information stealer that employs a unique approach for delivery and intrusion. Unlike traditional methods, it has been observed delivering malware through VBScript (VBS) files, which are typically used for legitimate Windows automation tasks. This malware operates by initially executing PowerShell commands, followed by leveraging steganography to hide its true intentions within an image file. The ultimate goal is to inject a malicious payload into a trusted Windows process, 'RegAsm.exe,' making detection and analysis more challenging. Agent Tesla's primary objectives include data theft from web browsers, email clients, and system information, which it then exfiltrates via SMTP communication.[/subscribe_to_unlock_form]

Summary:

Agent Tesla is a sophisticated Remote Access Trojan (RAT) and information stealer that employs a unique approach for delivery and intrusion. Unlike traditional methods, it has been observed delivering malware through VBScript (VBS) files, which are typically used for legitimate Windows automation tasks. This malware operates by initially executing PowerShell commands, followed by leveraging steganography to hide its true intentions within an image file. The ultimate goal is to inject a malicious payload into a trusted Windows process, 'RegAsm.exe,' making detection and analysis more challenging. Agent Tesla's primary objectives include data theft from web browsers, email clients, and system information, which it then exfiltrates via SMTP communication.[emaillocker id="1283"]

Execution Flow

Agent Tesla's infection process involves several intricate stages. It begins with deceptive emails containing VBS attachments that trigger malware installation. The VBS file executes PowerShell commands, which are obfuscated to evade detection. These commands instruct the download of a concealed image containing encoded instructions. This encoded data is decoded to reveal a .NET DLL file, which is then injected into 'RegAsm.exe' using a series of API calls for process injection. The malware collects data from web browsers, email clients, and system information, all concealed through obfuscation. Exfiltration is achieved through SMTP communication, using compromised email accounts for stealthy data transmission.

Agent Tesla's unique approach to delivery and intrusion showcases its sophistication as a Remote Access Trojan. By utilizing VBS files, steganography, and process injection into a trusted Windows utility, it successfully evades detection and analysis. The malware's ability to steal data from web browsers, email clients, and system information, coupled with its efficient exfiltration via SMTP, highlights its data-stealing capabilities.Security professionals must remain vigilant and employ advanced threat detection techniques to mitigate the risks associated with Agent Tesla and similar malware strains.

Threat Profile:

 References:

The following reports contain further technical details:

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/agent-teslas-unique-approach-vbs-and-steganography-for-delivery-and-intrusion/

[/emaillocker]
crossmenu