Saturday, February 22, 2025
HomeCyber Security NewsAgentTesla Stealer Delivered Via Weaponized PDF and CHM Files

AgentTesla Stealer Delivered Via Weaponized PDF and CHM Files

Published on

SIEM as a Service

Follow Us on Google News

AgentTesla, a notorious information stealer, is observed spreading via CHM and PDF Files, which covertly harvest critical information from the victim’s computer.

The stealer has features including keylogging, clipboard data capture, file system access, and data transfer to a Command and Control (C&C) server.

According to CRIL, its tactical changes maintain its serious threat to organizations and allow it to continue accessing priceless data.

Due to its adaptability, it may be used to exploit a variety of attack vectors, including email attachments, malicious URLs, and document-based intrusions.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

AgentTesla Delivered Via CHM File

An AgentTesla infection begins on the victim’s computer by a PowerShell script retrieved through a spam email containing a CHM file. 

A lure is used in the specially designed CHM file. Based on the information in the CHM file, it appears to be aimed at people or organizations working in network engineering, telecommunications, or information technology.

Malicious CHM file
Malicious CHM file

This CHM file secretly downloads and runs a PowerShell script from the remote server when the user opens it. The PowerShell script conceals harmful code by using encoded binary strings.

Infection Chain
Infection Chain

The malicious PowerShell script drops a loader DLL file based on the .NET framework, which injects the AgentTesla payload into system executables.

AgentTesla Delivered Via PDF File

In this case, this PDF uses two different strategies to spread the infection. In the first technique, the PDF triggers a PowerShell command that loads the AgentTesla malware. 

Two URLs Embedded in the PDF File
Two URLs Embedded in the PDF File

The second technique shows a fake message when the PDF is accessed, and when users click the “Reload” button, a PPAM file is downloaded.

The PowerShell operations executed by this PPAM file download the AgentTesla malware.

Recommendations

  • Use effective email filtering solutions to identify and stop spam, phishing scams, and harmful attachments.  
  • Avoid clicking on dubious links and opening email attachments.
  • Install a trusted Internet security and antivirus software on all of your linked devices.

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...