Hackers are exploiting a Microsoft Office to spread the Agent Tesla malware via malicious Excel.

The vulnerability exploited by hackers is CVE-2017-11882 and allows code execution with user privileges.
See also: MrAnon Stealer: Malware that pretends to be a booking service
The infection involves an obscure DLL containing a malicious JPG file, with the hidden DLL being activated via RegAsm.exe. Agent Tesla is an advanced keylogger and Trojandesigned to obtain sensitive information remotely. Hackers are constantly adapting their methods, highlighting the need for organizations to stay informed and protected from invisible cyber.
Threats are evolving as old security flaws become new attack targets. This week, Imperva revealed that the 8220 gang is exploiting a three-year-old vulnerability in Oracle WebLogic Server (CVE-2020-14883, CVSS score: 7.2) to mine cryptocurrency.
The malware increases its threat by presenting itself as a service (MaaS) and replacing QakBot after its removal in August 2023. DarkGate attacks have a serious impact on the technology sector, while threat actors adapt and change strategies to attack from time to time.
Additionally, there has been an increase in phishingtargeting hotel reservations. These attacks use emails that pretend to be hotel reservations and infect with malware, such as RedLine Stealer and Vidar Stealer. The strategy involves initial communication via email, with the attack evolving after the target responds.
Read more: Microsoft Excel: Will let you run Python scripts as formulas

Additionally, phishing campaigns posing as Instagram copyright messages have been discovered to steal two-factor authentication (2FA) backup codes. These attacks seek to bypass account protection measures through website fraud
Source: thehackernews.com
