HomeSecurityAgent Tesla trojan: WIM attachments used to distribute it

Agent Tesla trojan: WIM attachments are used to distribute it

A threat actor uses an unusual attachment (WIM) to bypass security software in order to distribute the Agent Tesla remote access trojan.

Tesla Agent

See also: Bizarro banking trojan: Targets bank customers in Europe and America

As secure email gateways and security software become more advanced and adapt to ever-changing phishing campaigns, threat actors are resorting to more unusual file formats to evade detection.

In the past, phishing scams disguised themselves as unusual attachments, such as ISO files or TAR files that are not commonly found as email attachments.

However, as threat actors adopt new and unusual attachments, cybersecurity companies are adding further detections to block them.

See also: QBot trojan replaces IcedID in malspam campaigns!

Using WIM to bypass security

In a new report from Trustwave, researchers explain how a threat actor has begun using WIM (Windows Imaging Format) attachments to distribute the Agent Tesla remote access trojan.

"All WIM files we collected from our samples contain Agent Tesla malware. This threat is a Remote Access Trojan (RAT) written in .Net that can take full control of a compromised system and can exfiltrate data via HTTP, SMTP, FTP, and Telegram," Trustwave security researcher Diana Lopera explains in the report.

These campaigns start with phishing emails pretending to send information from DHL or Alpha Trans, as seen below.

Agent Tesla trojan: WIM attachments are used to distribute it

The emails include .wim attachments (sometimes ending in .wim or .wim.001) which are designed to bypass security software.

Windows Imaging Format (WIM) files are a file-based disk image format that Microsoft developed to aid in the development of Windows Vista and later operating systems.

WIM files are used to package an entire drive, with all its files and folders, into a single file for easy distribution.

See also: Janeleiro: The new banking trojan targeting organizations and governments

As you can see below, when you open one of these WIM attachments in a hex editor, it clearly shows that an executable is embedded within it.

Tesla Agent

However, while WIM files may be less likely to be detected, phishing campaigns that use them have a bigger problem, as Windows does not have a built-in mechanism for opening a WIM file.

Therefore, when a user tries to open the attachment in Windows, a message will appear asking them to choose which program to open the file with, as shown below.

Agent Tesla trojan: WIM attachments are used to distribute it

This file format would then require a recipient to go out of their way and extract the file using a program like 7-zip and then double-click the file within it, which is highly unlikely to happen.

Tesla Agent

While using an unusual attachment can bypass some security filters, it is also a double-edged sword for the hacker.

Secure email gateways will almost certainly block these attachments. However, if you encounter an email with a WIM attachment, simply delete it as no legitimate email provider uses this file format.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS