Phishing Wave Poses as Mask Supplier, Drops Agent Tesla RAT
A phishing campaign active since May 2020 is using the global shortage of face masks and forehead thermometers as a lure to distribute Agent Tesla, a Remote Access Trojan (RAT) sold as Malware-as-a-Service (MaaS). The campaign targets companies across multiple industry verticals, spoofing legitimate chemical manufacturers and import/export firms to make fraudulent emails appear credible.
Campaign Structure and Evasion Tactics
The attacker rotates through a 10-day cycle, modifying Tactics, Techniques, and Procedures (TTPs) with each wave. These changes include rotating to new sender IP addresses, recompiling the malware to generate new hashes, and periodically shifting the impersonated company. One recent example spoofs Transchem Inc., a legitimate chemical supplier. In earlier versions, the attacker included the real email address of the purported sender in the signature block; this detail was removed in later iterations to reduce detection risk.
The phishing emails exploit weaknesses in email authentication protocol implementations, including DMARC, SPF, and DKIM, allowing the attacker to successfully spoof legitimate sender domains. Even when these protocols are configured correctly, the campaign demonstrates they are insufficient to stop dynamic phishing attacks on their own.
To present an authentic façade, the attacker impersonates real employees, includes legitimate company logos, accurate mailing addresses and contact details, and links to the spoofed company's actual website. The attachment is always named Supplier-Face Mask Forehead Thermometer.pdf.gz. The double extension exploits operating systems that hide known file extensions by default, leading victims to believe they are opening a PDF when the file is actually a compressed executable. Some legacy security vendors inspect only file extensions rather than file properties, allowing this file to bypass rule-based filtering.
Malware Execution and Capabilities
The initial infection requires user action: the target must extract the compressed attachment and click the resulting file, Supplier-Face Mask Forehead Thermometer.pdf.exe. This 32-bit Windows executable appears as a benign application but contains hidden malicious functionality. During execution, it checks whether it is running in a malware analysis environment; if so, the program goes dormant rather than proceeding with the attack.
When executed on a target device, the malware establishes a connection to the attacker's command and control (C2) server at us2[.]smtp[.]mailhostbox[.]com. This initial connection contains no stolen data; it simply confirms to the attacker that the malware ran successfully. The malware then attempts to read the victim's AppData folder, which typically contains credentials for browsers and email clients. It loads missing DLLs and downloads additional files to exfiltrate this data.
Exfiltration occurs via SMTP, a tactic that often escapes scrutiny because outgoing emails containing sensitive information are unlikely to be flagged unless Data Loss Prevention (DLP) software is deployed. The stolen information is then accessible to the attacker through the Agent Tesla dashboard UI for use in subsequent attacks.
Evolutionary Code Updates
Agent Tesla first appeared in 2014 but has gained renewed traction as a preferred MaaS platform, even superseding TrickBot and Emotet in popularity. The malware's primary advantage is its adaptability, with paid tiers offering additional licenses and functionality. A torrent of the malware is also circulating on Russian websites.
Each wave of this campaign incorporates advanced obfuscation to evade antivirus detection. The attacker generates new hashes by writing executables for the .NET framework and recompiling with alternative feature sets. Anti-debugging methods are also employed, including checks for the presence of a debugger, plus techniques to hide threads and breakpoints from reverse engineering tools.
Mitigation and Response
Organizations that suspect a compromise should run a full system scan and ensure all software and OS updates are applied on a routine basis. However, reliance on email gateways, cloud email suites, and traditional antivirus is insufficient given the threat actor's continuous evolution and use of commodity malware like Agent Tesla.
End-user awareness remains a critical defense layer. Employees should treat unsolicited emails from unknown companies with suspicion and report them to the security team. Compressed file attachments warrant extreme caution, and executable files should never be opened. These verifications require minimal effort but meaningfully reduce organizational exposure to this campaign.
Indicators of Compromise
Attachment: Supplier-Face Mask Forehead Thermometer.pdf.gz
- MD5:
fdfaaf9efb8507262ee9b97324bbb69a - SHA1:
846da85a2f2e6e79ebc7ed84b00ed97af513c80f - SHA256:
b419849ce915ede72fda1ea0b566651e233ef5eaffbf8b9211bd44085407ad5e
Executable: Supplier-Face Mask Forehead Thermometer.pdf.exe
- MD5:
64bc654373549584f7e596de24e1d8cc - SHA1:
6a39bd3ddaa2c9846e2a4912a80fd718eaee622f - SHA256:
53445247552485c277400bafba84458670f0c1001c91b4f0bcc15935c12d662b
Command and Control Server:
us2[.]smtp[.]mailhostbox[.]com
Sender IP Addresses:
209[.]58[.]149[.]65203[.]188[.]252[.]14185[.]66[.]40[.]3650[.]28[.]40[.]15362[.]210[.]83[.]13672[.]32[.]232[.]13695[.]216[.]16[.]146209[.]58[.]149[.]6689[.]33[.]246[.]113178[.]239[.]161[.]164156[.]96[.]47[.]65209[.]58[.]149[.]6995[.]211[.]208[.]50209[.]58[.]149[.]8737[.]48[.]85[.]232208[.]91[.]199[.]224



