APTMembers
APT

Fake Payment-Receipt RAR Hides JS Downloader for AgentTesla

A Spanish-language RAR lure claiming to be payment receipt details unpacks into a JavaScript downloader that fetches AgentTesla-class stealers. Detection engines flag the script nearly twice as often as its RAR container, exposing a gap gateway-level scanning misses.

Aug 14, 2026, 14:45 (UTC+9)Last seenAug 22, 2026Severity100ByCTX TeamActorTA505Hive0065IOC6RegionsATCYDEEGES

A Spanish-language RAR attachment titled "Detalles de los recibos de pago" — payment receipt details — carries a single embedded JavaScript file that a sandbox platform ultimately traces to AgentTesla-class credential theft. What makes this cluster worth a second look is not the lure itself, which is unremarkable, but the mismatch in how security engines treat its two stages: the RAR container is flagged by 13 of 76 engines, while the JavaScript it unpacks into is flagged by 31 of 76 — nearly…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence