An old password-stealing malware called Agent Tesla is back and nastier than ever

A new version of the remote access Trojan known as Agent Tesla has resurfaced, this time distributing what researchers have found is an updated version of the malware by using an infected email attachment that aims to steal everything from username and password credentials to a victim’s cryptocurrency.

This malware is actually pretty common and has been around since at least 2014. Researchers at Fortinet in a newly published threat research report note that it’s via a Microsoft Excel document attached to a spam email whereby the malware downloads and executes several pieces of code. “This malware,” the researchers explain, “is used to hijack bitcoin address information and deliver a new variant of Agent Tesla onto the victim’s device.” Regarding Agent Tesla, the researchers continue: “Most attackers like to spread malware in phishing emails. As a result, new phishing campaigns are detected every day by FortiGuard Labs. People should be more careful when opening files attached to email.”

Today’s Top Deal Amazon has real diamond stud earrings for under $60 — and the reviews are off the charts! Price:$59.90 Available from Amazon, BGR may receive a commission Buy Now Available from Amazon BGR may receive a commission

Per reporting from ZDNet, the email that’s used as a vector for this attack is crafted to resemble a legitimate business email, with one such sample malicious email as part of this campaign including an Excel attachment titled “Order Requirements and Specs” that the recipient is asked to open. Once they do so, Agent Tesla is downloaded onto the victim’s machine.

Earlier this year, Sophos researchers warned that Agent Tesla is a particularly resilient and pernicious threat. “For many months, it has remained among the top families of malware in malicious attachments caught by Sophos. Because of this sustained stream of Agent Tesla attacks, we believe that the malware will continue to be updated and modified by its developers to evade endpoint and email protection tools.” It was also noted that among the new abilities of this updated Agent Tesla variant is that it can now take data from the Windows clipboard, in addition to the number of applications it can target having been expanded “considerably.”

The protections that are recommended to help keep users safe from threats like these are the same as always and no surprise. Sophos, for example, notes that the email accounts used to spread Agent Tesla tend to be legitimate accounts that have been compromised. For that reason, one should never click open an email thoughtlessly, nor automatically open any attachments those emails contain. “Organizations and individuals should, as always, treat email attachments from unknown senders with caution, and verify attachments before opening them,” Sophos adds.

Related coverage:

Today’s Top Deal Free Echo Dot with when you buy a $45 Ring Video Doorbell in this crazy early Prime Day deal! Price:Was $100, Now $44.99 Available from Amazon, BGR may receive a commission Buy Now Available from Amazon BGR may receive a commission

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechiLive.in is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.