A wave of ongoing campaigns dropping well-known information-stealer like Agent Tesla, Loki-bot and others since at least January 2019. The adversaries using custom droppers, which inject the final malware into common processes on the victim machine. Once infected, the malware can steal information from many popular pieces of software, including Google Chrome, Safari and Firefox web browsers. In this blog post, we’ll walk through one of these campaigns in detail and how the different stages of the dropper hide the malware.”]
Source: https://blog.talosintelligence.com/2019/11/custom-dropper-hide-and-seek.html

