Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED," including such notable malware as Formbook, Lokibot and Agent Tesla. Based on our research, SWEED — which has been operating since at least 2017 — primarily targets their victims with stealers and remote access trojans. SWEED remains consistent across most of their campaigns in their use of spear-phishing emails with malicious attachments. While these campaigns have featured a myriad of different types of malicious documents, the actor primarily tries to infect its victims with a packed version of Agent Tesla — an information stealer that's been around since at least 2014. The version of Agent Tesla that SWEED is using differs slightly from what we've seen in the past in the way that it is packed, as well as how it infects the system. In this post, we'll run down each campaign we're able to connect to SWEED, and talk about some of the actor's tactics, techniques and procedures (TTPs).

AI Analysis

· 1 week ago

Executive Summary

The SWEED threat actor has been actively distributing malware campaigns since at least 2017, primarily targeting victims with information stealers like Formbook and Agent Tesla through spear-phishing emails. The actor is known for consistently using malicious attachments to deliver payloads, focusing on sectors such as retail and finance in the United States and European Union. SWEED's operations demonstrate a moderate level of sophistication, with a focus on stealing credentials and financial data.

Goals & Targeting

SWEED's primary objective appears to be the theft of sensitive information, including credentials and financial data, from targeted individuals and organizations. The actor's focus on retail and financial sectors suggests an interest in accessing personally identifiable information (PII) and financial records. By leveraging spear-phishing campaigns, SWEED aims to compromise end-users within target organizations, allowing for the deployment of remote access trojans and information stealers. The consistent use of malicious Office document attachments indicates a preference for methods that can bypass basic email filtering mechanisms while remaining somewhat stealthy.

Enhanced Description

SWEED has emerged as a persistent threat actor engaged in numerous malware distribution campaigns since at least 2017. The group primarily delivers information stealers such as Formbook, Lokibot, and Agent Tesla to its victims, often through sophisticated spear-phishing techniques involving malicious Office document attachments. While the campaigns have employed various methods of delivery, SWEED has consistently relied on malicious scripts packed within these documents to infect systems. The actor's use of custom packing techniques for Agent Tesla highlights a level of operational creativity, though the core methodology remains consistent across campaigns. SWEED's targeting focus appears to be on sectors with sensitive personal and financial data, such as retail and financial services, particularly in the United States and European Union.

Key Capabilities

  • Spear-phishing emails with malicious Office document attachments
  • Distribution of Remote Access Trojans (RATs)
  • Use of custom packing techniques for malware delivery
  • Ability to persist on compromised systems

MITRE ATT&CK Tactics

Initial Access
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1066.001
T1059.003
T1566.002
T1078
T1003.001
T1074

Software / Tooling

Formbook
Lokibot
Agent Tesla
Malicious Office document templates

Campaigns & Victims

SWEED has been involved in numerous campaigns targeting individuals and organizations across various industries, with a particular emphasis on sectors where sensitive information is stored. The consistent use of spear-phishing emails with malicious attachments suggests a deliberate operational strategy to maximize infection rates while minimizing detection. Campaigns have varied in their specific tactics but have remained true to the core methodology of delivering known malware families like Agent Tesla. Notable past operations include the distribution of Formbook and Lokibot, with campaigns often leveraging different malwares to evase detection. The actor's operational tempo appears steady, with ongoing activity observed across multiple years.

IOC Patterns

  • Spear-phishing emails with macro-laced Office document attachments
  • Distribution of malware via malicious URLs or links in phishing emails
  • Binary packing techniques for malware distribution

Recommended Actions

  • Implement advanced email filtering to detect and block spear-phishing attempts
  • Deploy endpoint detection and response (EDR) solutions to monitor for known malware families like Formbook and Agent Tesla
  • Conduct regular user training on phishing recognition and safe email handling practices
  • Enhance network monitoring for signs of C2 communication or data exfiltration attempts
  • Use application whitelisting to prevent execution of unauthorized binaries
  • Apply robust patching management to mitigate vulnerabilities exploited by the actor

Suggested Tags

Malware campaigns
Financial malware
Retail sector attacks
Phishing
Information theft

Confidence Assessment

There is a high level of confidence in the information regarding SWEED's activities and TTPs due to extensive research by Cisco Talos. However, gaps exist in understanding the full scope of the actor's infrastructure and long-term objectives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2
Malware campaigns
Financial malware
Retail sector attacks
Information theft

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.