
8/27/2020 · Elaine Dzuba
What this post added
This post details a specific phishing campaign that uses Agent Tesla malware, disguised as a face mask manufacturer, to target companies. It analyzes the campaign's social engineering tactics, evasion techniques (rotating IP addresses, modifying malware hashes, exploiting email authentication flaws), and the malware's functionality (keylogging, information stealing via SMTP). It also highlights the limitations of legacy security vendors and traditional AV, emphasizing the need for advanced, real-time detection like that provided by Area 1 Security's ML/AI technology.