Summary:
Researchers revealed a sophisticated attack leveraging the ZPAQ compression format and a deceptive use of the .wav file extension to deliver Agent Tesla, a notorious .NET-based information stealer. ZPAQ, though offering superior compression and journaling functions, suffers from limited software support, primarily requiring a command-line tool for extraction. The threat actor cleverly disguised the malicious payload as a PDF file within a ZPAQ archive, exploiting the format's lesser-known nature. This choice aimed to evade automated scanning systems and enhance the attack's efficacy.[/subscribe_to_unlock_form]
Summary:
Researchers revealed a sophisticated attack leveraging the ZPAQ compression format and a deceptive use of the .wav file extension to deliver Agent Tesla, a notorious .NET-based information stealer. ZPAQ, though offering superior compression and journaling functions, suffers from limited software support, primarily requiring a command-line tool for extraction. The threat actor cleverly disguised the malicious payload as a PDF file within a ZPAQ archive, exploiting the format's lesser-known nature. This choice aimed to evade automated scanning systems and enhance the attack's efficacy.[emaillocker id="1283"]
The phishing attempt unveiled a complex attack strategy beginning with the ZPAQ compression format, known for its superior compression ratio and journaling functions. The threat actor ingeniously named the initial file "Purchase Order pdf.zpaq," enticing users to believe it contained a PDF file. However, upon extraction, the 6KB archive revealed a 1GB .NET executable filled predominantly with zero bytes. This deliberate bloat served as an effective evasion tactic, preventing automatic scanning systems and sandboxes from detecting the malicious payload. The executable's analysis in a hex editor disclosed its lack of entropy in the overlay section, further confirming the zero-byte strategy. This technique, coupled with the deceptive use of ZPAQ, exemplifies a sophisticated attempt to exploit the limitations of widely adopted security measures.
The primary function of the unarchived .NET executable was to download and decrypt a file with a .wav extension, although its content had no relation to audio. The .wav file, chosen for its commonplace nature, provided cover for malicious activities and facilitated covert communication. The attackers leveraged the Telegram API as a command and control (C&C) channel, capitalizing on its firewall-friendly traffic. Telegram specific details of the Telegram bot malware remained elusive due to authorization challenges during analysis, it became evident that the threat actor, beyond Telegram, also utilized FTP and SMTP for communication.
The utilization of the ZPAQ compression format raised concerns about targeted attacks on individuals with technical knowledge or the testing of unconventional techniques to propagate malware. The attackers demonstrated a keen understanding of evasive tactics, utilizing less-known archive tools and exploiting widely used file extensions for concealment. Agent Tesla's multifaceted capabilities underscored the ongoing challenges faced by cybersecurity professionals. The continuous evolution of such threats necessitates proactive measures, including robust malware protection, heightened security awareness, and regular software updates to mitigate potential risks and protect both individuals and organizations from sophisticated cyber threats.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/11/new-agent-tesla-malware-variant-using.html
[/emaillocker]