Agent Tesla LATAM Operation — 18-Month Credential Theft Campaign Against Chilean Enterprises via .NET Reactor 6.x Loader & aspnet_compiler.exe Process Hollowing — Threadlinqs Intelligence
As of 2026-05-30, Agent Tesla LATAM Operation — 18-Month Credential Theft Campaign Against Chilean Enterprises via .NET Reactor 6.x Loader & aspnet_compiler.exe Process Hollowing is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-0525 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Persistent Agent Tesla credential-theft operation against Chilean and broader LATAM enterprises, active since mid-2024 with 80+ correlated samples. Spanish-language procurement/payroll lures deliver a
ANY.RUN researcher Moises Cerqueira (2026-05-14) disclosed a sustained Agent Tesla campaign targeting Chilean enterprises and adjacent LATAM organizations across finance, procurement, accounts payable, and B2B verticals. The operator infrastructure — anchored on the compromised Romanian hospitality domain horeca-bucuresti.ro — has been active since at least mid-2024, with more than 80 distinct samples observed communicating with the same FTP credentials over an 18+ month window. The campaign weaponizes Agent Tesla, a commercial .NET keylogger/infostealer in continuous distribution since 2014, behind a hardened delivery and execution chain designed to defeat static AV, sandboxed analysis, and on-disk endpoint inspection.
Initial access is via Spanish-language spear-phishing emails carrying RAR archives that masquerade as purchase orders, payroll, and payment receipts (e.g., ''Orden de compra_pdf.uu'', ''Nómina de sueldos.pdf_008.exe'', ''Comprobante de pago.pdf.exe''). Upon extraction, a JScript-encoded (.jse) dropper executes under wscript.exe, drops randomized-name PowerShell stagers to C:\Temp\ (observed names AYRMWWFH.ps1, Z2KBLYG5.ps1, ELHYLTLT.ps1), and opens a decoy PDF for victim plausibility. The PowerShell stager launches with ExecutionPolicy Bypass and reflectively loads ALTERNATE.dll — a .NET assembly protected by Eziriz .NET Reactor 6.x with control-flow obfuscation, calls encryption, virtualization, and anti-ILDASM tampering enabled.
ALTERNATE.dll extracts an embedded encrypted resource representing the Agent Tesla payload. Decryption uses RijndaelManaged in CBC mode with a 256-bit key, the 16-byte IV prepended to the ciphertext; the plaintext is then decompressed via DeflateStream. Four AES key candidates have been recovered across samples (SHA-256: D5B7247C…, C61B1941…, C356AFF1…, F1C3EBE7…), enabling deterministic offline decryption of additional samples that reuse the loader.
Execution then pivots to Process Hollowing of the trusted Microsoft binary aspnet_compiler.exe (the ASP.NET precompilation utility, signed and present on every modern .NET-equipped Windows host). The loader spawns aspnet_compiler.exe in a suspended state, calls ZwUnmapViewOfSection to evict its image, VirtualAllocEx-allocates RWX memory at the original base, WriteProcessMemory-writes the decrypted Agent Tesla image, SetThreadContext-rewires the entry point, and ResumeThread to detonate. After hollowing, Agent Tesla runs fileless inside a Microsoft-signed process, defeating image-load and signature-based controls and evading EDR rules that whitelist Microsoft binaries.
Before exfiltration, Agent Tesla performs a sandbox/hosting fingerprint by GET-ing http://ip-api.com/line/?fields=hosting and parsing the boolean response — if the host is flagged as a hosting provider (typical of sandboxes and VMs), payload activity is suppressed. On real victims, Agent Tesla harvests credentials from 28+ browsers (Chrome, Edge, Firefox, Brave, Opera and forks), 21+ email clients (Outlook, Thunderbird, IncrediMail, eM Client), 9 FTP clients (FileZilla, WinSCP, CoreFTP, FlashFXP), 5 VPN clients (NordVPN, OpenVPN, Private Internet Access), 13 VNC servers, and 8+ messaging applications (Pidgin, Trillian, Psi). It also runs a polling keylogger, clipboard hijacker, and periodic screenshot capture.
Collection output is serialized into an HTML report named ''PW_{username}-{hostname}_{YYYY_MM_DD_HH_MM_SS}.html'' and uploaded via cleartext FTP to ftp.horeca-bucuresti.ro using the operator account americas2@horeca-bucuresti.ro on the default FTP port. Because credentials travel unencrypted, the campaign is observable to any on-path network sensor that decodes FTP. Mutexes ''roSkM'' (primary) and ''hdfzpysvpzimorhk'' (secondary) and the campaign tag ''HnJnO'' anchor cross-sample clustering, and the persistence binary 7bcd610d-7af6-4dc2-875b-dc4fec91463c.exe has been observed as a recurring artifact.
The campaign''s operational discipline — 18-month infrastructur
Weaknesses (CWE)
CWE-94, CWE-913, CWE-319
Target sectors: finance, procurement, accounts payable, manufacturing, b2b enterprise, logistics
Target regions: Chile, Latin America, South America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1059, T1047, T1055, T1027, T1027, T1140, T1218