Researchers at Area 1 Security have discovered a phishing campaign operating on a global scale, purporting to provide information about face masks and other personal protective equipment, in the context of the pandemic , with the aim of infecting devices with the AgentTesla remote access Trojan.
Security researchers first discovered the AgentTesla Trojan in 2014, and it is now available for rent on various underground forums, with prices ranging from $12 for a monthly rental to $35 for a six-month lease, according to a report from Sentinal Labs released earlier this month.

The campaign, which appears to have begun in May, uses phishing emails that spoof messages from chemical manufacturers, as well as import/export businesses.
It is noteworthy that the scammers behind this campaign change their tactics, techniques, and procedures every 10 days, modifying the messages and spoofed domainsso that they cannot be detected.
These phishing emails are estimated to have targeted thousands of incoming users, although the rate of the attack has slowed since August 13. According to Juliette Cash, a threat researcher at Area 1 Security, this may mean that the scammers are taking a break to refresh and strengthen their strategies once again.

The phishing campaign in question targets companies worldwide, covering various industrial sectors, including American international companies. The campaign's target has previously included and today includes executives of Fortune 500 companies, including security directors from every corner of the globe. Additionally, it is believed that the attackers use more than one “weapons” to lure unsuspecting victims.
The phishing emails sent as part of the campaign aim to infect devices with AgentTesla, a one-time information stealer that has evolved into a remote access Trojan or RAT. Since the outbreak of the COVID-19 pandemic, this malware has become popular with scammers and cybercriminals due to its ability to evade detection as well as low licensing fees on underground forums, making it affordable for rental and deployment.

The phishing campaign forges legitimate companies that advertise protective face masks as well as other medical items used to prevent the spread of COVID-19. One of those companies was the chemical supplier “Transchem”. Additionally, the messages sometimes use employee names to add another level of legitimacy.
During the campaign, the scammers rotate IP addresses to bypass certain security protections and take advantage of misconfigured email authentication protocols, such as DMARC, in order to deliver malicious emails to victims' inboxes.

The phishing emails contain an attachment that looks like a PDF file and is usually named: “Vendor-Face Mask Forehead Thermometer.pdf.gz” . If the file is opened and unzipped, macros are activated and the AgentTesla Trojan is transferred to the compromised device. Once transferred to a device, the AgentTesla Trojan connects to a command-and-control server to receive additional instructions from the crooks. The malware typically gains access to the AppData folder that contains settings, files, and data for Windows applications . It will then attempt to load the missing “dynamic link links” and download additional files in order to remove the stolen information from the AppData folder. The crooks try to collect as much data as possible from the compromised devices. Among the items that can be collected via the AgentTesla Trojan are configuration data as well as credentials from web browsers, email, VPN , and FTP. However, because AgentTesla is a remote access Trojan, it exposes affected devices to other, and potentially more damaging, attacks .
While the AgentTesla Trojan has appeared in BEC scams originating from Nigeria, security firm Bitdefender reported in April that the malware has also been used in a series of attacks targeting the global oil and gas industry. Also in April, researchers at Palo Alto Networks' Unit 42 noticed a significant increase in COVID-19-themed phishing emails that attempted to deploy the Trojan across a wide range of industries.
