FILEMembers
FILE

Fake Shipping Documents Deliver AgentTesla Stealer Under Five Packers

A phishing campaign disguised as vessel particulars sheets drops a commodity AgentTesla infostealer wrapped in five commercial .NET obfuscators. The double-extension lure targets shipping and freight-forwarding staff used to receiving cargo paperwork by email.

Aug 2, 2026, 05:49 (UTC+9)Last seenAug 2, 2026Severity74ByCTX TeamActorAPT29MinidionisIOC11MITRE38

The payload doesn't look like malware when it lands in an inbox. It looks like a vessel particulars sheet — "MV TBN SHIP PARTICULARS.docx.exe," "SHIP PARTICULARS - MV OSTC01.xlsx.exe," "MV PACIFIC ENDEAVOR V2202 PARTICULARS I.docx.exe." Each of those alternate filenames belongs to the same 490KB Windows executable, a double-extension trick that hides an EXE behind a familiar Word or Excel icon — a lure built for whoever in a shipping or freight-forwarding chain is used to receiving cargo…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence