• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new agent tesla malware variant using zpaq compression in email

New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks

You are here: Home / General Cyber Security News / New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks
November 21, 2023

A new variant of the Agent Tesla malware has been observed delivered by using a lure file with the ZPAQ compression structure to harvest information from numerous email purchasers and nearly 40 web browsers.

“ZPAQ is a file compression structure that delivers a greater compression ratio and journaling function in contrast to greatly utilised formats like ZIP and RAR,” G Details malware analyst Anna Lvova said in a Monday investigation.

“That suggests that ZPAQ archives can be smaller sized, saving storage area and bandwidth when transferring information. Nonetheless, ZPAQ has the greatest drawback: confined software assist.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

Initially appearing in 2014, Agent Tesla is a keylogger and remote accessibility trojan (RAT) published in .NET that’s provided to other danger actors as portion of a malware-as-a-assistance (MaaS) design.

It truly is often utilised as a to start with-phase payload, supplying remote accessibility to a compromised technique and utilized to down load much more innovative 2nd-phase applications this sort of as ransomware.

Agent Tesla is generally delivered through phishing email messages, with current campaigns leveraging a six-calendar year-outdated memory corruption vulnerability in Microsoft Office’s Equation Editor (CVE-2017-11882).

Agent Tesla Malware

The most current attack chain starts with an email that contains a ZPAQ file attachment that purports to be a PDF document, opening which extracts a bloated .NET executable that’s largely padded with zero bytes to artificially inflate the sample dimension to 1 GB in an work to bypass standard security measures.

“The principal function of the unarchived .NET executable is to down load a file with .wav extension and decrypt it,” Lvova defined. “Employing frequently utilized file extensions disguises the targeted visitors as ordinary, creating it far more difficult for network security alternatives to detect and prevent malicious exercise.”

Cybersecurity

The finish aim of the attack is to infect the endpoint with Agent Teslathat’s obfuscated with .NET Reactor, a genuine code defense computer software. Command-and-control (C2) communications is attained by means of Telegram.

The progress is a signal that menace actors are experimenting with unheard of file formats for malware shipping, necessitating that consumers be on the lookout for suspicious e-mail and preserve their systems up-to-date.

“The utilization of the ZPAQ compression structure raises much more questions than solutions,” Lvova stated. “The assumptions in this article are that both menace actors target a certain group of persons who have complex awareness or use a lot less broadly known archive instruments, or they are screening other methods to distribute malware a lot quicker and bypass security application.”

Located this posting intriguing? Stick to us on Twitter  and LinkedIn to study much more exclusive material we submit.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «how multi stage phishing attacks exploit qrs, captchas, and steganography How Multi-Stage Phishing Attacks Exploit QRs, CAPTCHAs, and Steganography
Next Post: Play Ransomware Goes Commercial – Now Offered as a Service to Cybercriminals play ransomware goes commercial now offered as a service»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.