Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

AgentTesla Being Distributed via Sophisticated PowerPoint Files

December 8, 2021

When the PowerPoint file is run, a security notice appears, where the user selects whether or not to enable macros just like in the previous cases. Selecting Enable macro runs the malicious macro. When the malicious macro is executed, an error notice appears disguised as a PowerPoint error, making it difficult for users to notice malicious behaviors. The malicious macro is executed automatically by the Auto_Open() function, and the data used for the malicious behavior is obfuscated. Unobfuscating it shows the strings below, and the malicious command is executed via the shell function. The malicious command executed by the malicious macro and just like in the previous cases, it approaches a malicious URL via mshta process to run additional scripts.