• For Enquiry
  • 847-868-9253
  • 847-868-9208
  • Home
  • Why Choose CIO Landing?
    • Our Team
    • Success Stories
    • ‘8 Things’ We Do Better
    • Partners & Certifications
    • Our Services
  • Industry Expertise
    • Manufacturing
    • Medical
    • Education
    • Financial Services
    • Non-Profit
    • Law Firms
  • IT Solutions
    • Co-Managed Service
    • Managed IT Services
    • IT Support
      • On Demand Services
      • Office Moves & Wiring
      • Security
    • Server Management
    • Backup & Disaster Recovery
    • Cloud Services
    • CIO & IT Consulting
    • Cybersecurity Services
    • VoIP
    • Managed Firewall
    • Microsoft 365
      • Microsoft 365 Plans
        • Small Business
        • Enterprise
        • Education
    • Hardware & Software Sales
    • Email & Spam Protection
  • Resources
    • Free Copy Of New Book
    • Blog
    • Newsletter
    • Video Tips
      • Video Tips Archive
    • Free Cloud Report
    • IT Buyers Guide
    • Cybersecurity Crisis Report
    • Network Audit
    • COVID 19 Resources
    • In The NEWS
    • Online Training
  • About Us
    • Our Mission
    • Leadership
    • Teams
    • Referral Program
    • Press Releases
      • CIO Landing: More Than Just an IT
      • Small businesses can have an IT department too
      • CIO Landing, Inc. has joined forces with Banc Certified Merchant Services (BCMS).
    • Affiliations
    • Careers
      • Job Descriptions
    • FAQs
    • Causes We Support
    • Privacy Policy
    • Terms & Conditions
  • Locations
    • Northfield, IL
    • Northbrook, IL
    • Chicago, IL
    • Miami, FL
  • Support
✕
Gmail Blocks Millions Of COVID-19 Phishing Emails Daily
April 28, 2020
Some Smart WiFi Linksys Routers May Need A Password Reset
April 30, 2020

Agent Tesla Malware Steals WiFi Passwords From Infected Users

April 29, 2020

A few new variants of the Agent Tesla info-stealer malware have been spotted in the wild and should be on your radar if they’re not already.

The new variants are more dangerous than previous versions of the malware. They now sport a module that enables them to scrape WiFi passwords from devices they invest.

That will enable them to lurk in the background and install additional malware later, even after the initial infection has been found and cleared. It also makes these new variants to compromise other systems that reside on, or connect to the same compromised wireless network.

The authors of the new variants took pains to heavily obfuscate the code to make it more difficult to detect. The new capabilities revolve around the addition of a combination of the “netsh” command, coupled with a “wlan show profile” argument that lists all available WiFi profiles in a convenient format.

To actually get at the passwords, once the netsh command is run, a key-clear argument is used to show and extract the password for each profile in plain text format.

A report compiled by Malwarebytes had this to say about the newly discovered code:

“In addition to wifi profiles, the executable collects extensive information about the system including FTP clients, browsers, file downloaders, machine info (username, computer name, OS name, CPU architecture, RAM) and adds them into a list. We believe this may be used as a mechanism to spread, or perhaps to set the stage for future attacks.”

Agent Tesla isn’t the only malware to have been upgraded in recent months. Emotet, which went for more than two years without a significant upgrade, has recently been spotted in the wilds sporting new WiFi stealing capabilities. It seems to point to a newly emerging trend in the hacking world.

Share
98
taylor
taylor

Related posts

March 10, 2025

The Hidden Threat: How Gift Card Scams Are Targeting Businesses Like Yours


Read more
February 11, 2025

CIO Landing Named to CRN’s MSP 500 List for 2025—For the Third Year in a Row!


Read more
December 4, 2024

Unlocking the Power of Windows 11: Tips for Maximum Productivity


Read more
© 2025 All Rights Reserved | Powered by CIO Landing