Bignosa is a threat actor delivering Cassandra Protector-secured Agent Tesla malware via phishing campaigns.
Analyst brief
Bignosa is a threat actor targeting Australian and US organizations through phishing campaigns that deliver Agent Tesla malware attachments protected by Cassandra Protector. They compromise servers by installing Plesk and RoundCube, accessing them via SSH and RDP, and use advanced obfuscation to evade detection. Bignosa collaborates with a cybercriminal known as Gods, demonstrating high operational sophistication. Defenders should focus on detecting protected Agent Tesla payloads in email attachments, monitor for unauthorized Plesk/RoundCube installations, and restrict SSH/RDP access.
Bignosa
unknown
Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla attachments protected by Cassandra Protector. They compromised servers by installing Plesk and RoundCube, connected via SSH and RDP, and used advanced obfuscation methods to evade detection. Bignosa collaborated with another cybercriminal named Gods, who provided advice and assistance in their malicious activities. The actor has been linked to multiple phishing attacks and malware distribution campaigns, showcasing a high level of sophistication in their operations.