Cybercriminals are targeting the oil and gas industry with highly targeted spearphishing campaigns impersonating shipping companies and engineering contractors while attempting to infect targets with Agent Tesla malware payloads.
Agent Tesla is a .Net-based information-stealing program commercially available since at least 2014 that comes with keylogging and remote access Trojan (RAT) capabilities.
This info-stealer is also used to collect system information, steal clipboard content, and kill processes related to malware analysis and antivirus solutions.
What makes these campaigns stand out is the fact that it is the first time Tesla has been deployed as part of attacks targeting the oil and gas sector.

Abuse of reputation and insider knowledge
While the attacks are not as sophisticated as others that have targeted companies , their timing is apt given that they were active before and during a week of marathon meetings and calls between the OPEC+ (Organization of the Petroleum Exporting Countries) alliance and the Group of 20 nations that ended with a historic agreement to reduce global oil production.
This “indicates motivation and interest to learn how specific countries plan to address the issue”, as described in detail in a report that was shared in advance with BleepingComputer by researchers at Bitdefender who identified and analyzed these attacks.
In one of the spearphishing campaigns, the hackers impersonated and abused the reputation of the Egyptian state oil company ENPPI (Engineering for Petroleum and Process Industries), a company with experience in oil and natural gas projects both onshore and offshore.
“The second spearphishing campaign used legitimate information about a chemical/oil tanker, as well as the industry, to make the email seem credible to victims from the Philippines,” the Bitdefender report states.
In both cases, the attackers used malicious attachments to deliver the Agent Tesla info-stealer, attempting to infect recipients and collect credentials and sensitive information transferred to their command and control servers.
The energy sector is becoming an increasingly frequent target in 2020
However, as also noted in a report, these attacks “also target other energy sectors that have been classified as critical during this Coronavirus pandemic.”
After reviewing the victims' profiles, Bitdefender found that the attackers are also targeting charcoal processing entities, large freight, plumbing plants, and raw material manufacturers.
“Since October 2019, the global trend of cyberattacks on the energy industry has been steadily increasing on a monthly basis, with February 2020 being the peak,” says Bitdefender.
“With over 5,000 malicious reports from companies operating in the energy sector, cybercriminals appear to be keenly interested in this sector, perhaps because it has become more important following recent fluctuations in oil prices.”
