Today's Malware Report looks at a stealer that, as recent CERT (Computer Emergency Response Team) reports indicate, has targeted the Italian market.
We are talking about Agent Tesla, a keylogger and info-stealer malware developed in .NET. It is able to collect credentials from a number of predefined applications and send them to its C&C (Command & Control), via HTTPs, SMTP (Simple Mail Transfer Protocol) or Telegram channel.
This malware family strikes through different vectors, such as Office documents, JavaScript or VBS scripts.
Specifically, our analysis focuses on a recent malicious executable submitted in the public tasks of AnyRun's online sandbox.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/