A phishing campaign is distributing Agent Tesla through Spanish-language business emails that impersonate purchase orders and invoices, targeting organizations across Latin America and Spain. Broadcom reported that the attack delivers a RAR attachment disguised as a PDF, then executes a multi-stage chain involving a JScript loader, PowerShell downloaders, an in-memory .NET loader, and a final Agent Tesla payload that runs largely in memory. The campaign uses obfuscation, masquerading, urgency-themed messaging, and an AMSI bypass to evade detection while minimizing disk artifacts.
The malware is designed to steal credentials, system information, and other sensitive data, then exfiltrate it over encrypted HTTP(S) channels. The activity aligns with earlier large-scale Agent Tesla spam operations that used polished corporate-themed lures and impersonated legitimate companies to infect business users at scale, with especially high impact in Mexico and Spain. Across observed campaigns, Agent Tesla variants have targeted credentials stored in browsers, email clients, FTP and VPN tools, remote access software, and messaging applications, while also supporting screenshot capture, keylogging, and clipboard theft.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Securelist states that Agent Tesla, a .NET-based information stealer, has been known since 2014. It is designed primarily to steal passwords and other sensitive data from infected systems.
Broadcom reports that Symantec identified a new phishing campaign using Spanish-language purchase-order lures to target organizations across Latin America, Spain, and other regions. The attack chain used a disguised RAR attachment, JScript and PowerShell stages, and an in-memory .NET loader to deploy Agent Tesla while evading detection.
Securelist says the 2022 campaign reached its highest monthly volume in June, when 194,100 malicious emails were detected. The emails used polished business-themed lures such as procurement requests and product inquiries.
Securelist reports a mass email campaign from April through August 2022 that impersonated real companies and delivered malicious archive attachments carrying Agent Tesla. Detection systems linked 739,749 messages to the campaign over that period.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.