AgentTesla Campaigns

Garden State Cyber Threat Highlight

Original Release Date: 4/12/2023

The NJCCIC observed multiple phishing campaigns sent from both US and non-US top-level domains (TLD) to New Jersey State employees in an attempt to deliver the AgentTesla malware – an advanced backdoor with keylogging capabilities used to steal credentials and exfiltrate data. They purport to be quotes for medical supplies or non-specific items listed in the body of the email. They also contain attachments as compressed executables (LZH and TAR.GZ files) and JPG files with keywords referencing “device images” and “new order-po.” These attachments claim to be quotes, specifications, or photos of the items that, if clicked, launch the executable to install AgentTesla. Additionally, emails contain spelling and grammatical errors and do not have personalized greetings.

The NJCCIC recommends users and organizations educate themselves and others on these continuing threats and tactics to reduce victimization. Users are advised to refrain from responding to unsolicited communications, clicking links or opening attachments from unknown senders, and exercise caution with communications from known senders. If unsure of the legitimacy, contact the sender via a separate means of communication, such as by phone, before taking action. Additionally, visit websites directly by manually typing the legitimate URL into a browser and refrain from navigating to online accounts via links delivered in emails. Phishing emails and other malicious cyber activity can be reported to the FBI Internet Crime Complaint Center (IC3) and the NJCCIC.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.