Cisco Talos has discovered a new malware campaign that drops the sophisticated information-stealing trojan called “Agent Tesla” The adversaries behind this malware use a well-known exploit chain, but modified it so that antivirus solutions don’t detect it. If undetected, Agent Tesla has the ability to steal user’s login information from a number of important pieces of software, such as Google Chrome, Mozilla Firefox, Microsoft Outlook and many others. In this post, we will outline the steps the adversaries took to remain undetected.”]
Source: https://blog.talosintelligence.com/2018/10/old-dog-new-tricks-analysing-new-rtf_15.html