Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosAnonymous Official: I'm begging you to understand this..(20.09.2026 um 21:30 Uhr)
Sichere ProgrammierungHow to Monitor Cron Jobs with a Simple HTTP Health Check(20.09.2026 um 23:14 Uhr)
Sichere ProgrammierungWhy my builds don't run on my laptop(20.09.2026 um 23:15 Uhr)
Sichere ProgrammierungDesigning offline-first when there's no server(20.09.2026 um 23:16 Uhr)
Sichere ProgrammierungSearching for Better Game Recommendations with Jev(20.09.2026 um 23:19 Uhr)
Linux Tipps & HardeningUbuntu 26.10 stops low memory from killing your desktop session(20.09.2026 um 19:55 Uhr)
YouTube Security VideosAnonymous Official: I'm begging you to understand this..(20.09.2026 um 21:30 Uhr)
Sichere ProgrammierungHow to Monitor Cron Jobs with a Simple HTTP Health Check(20.09.2026 um 23:14 Uhr)
Sichere ProgrammierungWhy my builds don't run on my laptop(20.09.2026 um 23:15 Uhr)
Sichere ProgrammierungDesigning offline-first when there's no server(20.09.2026 um 23:16 Uhr)
Sichere ProgrammierungSearching for Better Game Recommendations with Jev(20.09.2026 um 23:19 Uhr)
Linux Tipps & HardeningUbuntu 26.10 stops low memory from killing your desktop session(20.09.2026 um 19:55 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Threat Actors Exploit Microsoft Office Vulnerability to Spread Agent Tesla Malware

Reagiere als Erste:r — dein Feedback zählt!

Threat Actors Exploit Microsoft Office Vulnerability to Spread Agent Tesla Malware

Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.

Patreon
Reading Time: 3 Minutes
Threat actors have been observed exploiting an old Microsoft Office vulnerability, known as CVE-2017-11882, to propagate the Agent Tesla malware. This vulnerability, with a CVSS score of 7.8, has become a focal point for phishing campaigns aimed at spreading the spyware, which is designed to clandestinely collect keystrokes, system clipboard data, screenshots, and credentials from infected systems.
 
First discovered by experts in June 2018, Agent Tesla has been in circulation since 2014, initially distributed through a malicious Microsoft Word document containing an auto-executable VBA Macro. Once users enable the macro, the spyware is installed on their machines, allowing threat actors to conduct covert surveillance and data theft.

See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses

Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.

Recent phishing campaigns have seen attackers employing spam messages with keywords like “orders” and “invoices” to entice recipients into opening weaponized Excel documents, furthering the spread of the malware.
 
The CVE-2017-11882 flaw, a memory-corruption issue affecting all versions of Microsoft Office released in the past 17 years, including the latest Microsoft Office 365, poses a significant risk. This vulnerability can be triggered on all versions of the Windows operating system, including the latest Microsoft Windows 10 Creators Update. Specifically, the flaw affects the MS Office component EQNEDT32.EXE, responsible for the insertion and editing of equations in documents, and could be exploited by threat actors to execute malicious code in the context of the logged-in user.



Despite being patched in 2017, threat actors continue to exploit this vulnerability in the wild, with a recent surge in attacks leveraging the issue.
 
Zscaler’s report highlights the intricate tactics employed by threat actors to deliver Agent Tesla, emphasizing the need for organizations to remain vigilant and informed about evolving cyber threats to protect their digital infrastructure.
 
The obfuscated VBS file incorporates variable names that are 100 characters long, adding a layer of complexity to the analysis and deobfuscation process.
Subsequently, the obfuscated VBS file downloads a malicious JPG file containing a Base64-encoded DLL.
 
 
Agent Tesla phishing
 
Upon downloading the JPG file, the VBS file triggers a PowerShell executable, which retrieves the Base64-encoded DLL from the image, decodes it, and executes the malicious code embedded within the DLL.
 
“In addition to staying on top of these threats, Zscaler’s ThreatLabz team continuously monitors for new threats and shares its findings with the cybersecurity community,” concludes the report, underscoring the ongoing efforts to combat emerging cyber threats.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: [email protected]

Source: securityaffairs.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.


Join our Community

The post Threat Actors Exploit Microsoft Office Vulnerability to Spread Agent Tesla Malware first appeared on Black Hat Ethical Hacking.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Threat Actors Exploit Microsoft Office Vulnerability to Spread Agent Tesla Malware

Thematisch verwandte Begriffe: Threat, Actors, Exploit, Microsoft · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93957 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This a…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick