Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Aggah, TH-157

Description

Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims since the latter part of 2021.

AI Analysis

· 1 week ago

Executive Summary

Hagga, also known as Aggah or TH-157, is an unidentified threat actor suspected of utilizing Agent Tesla since late 2021 to steal sensitive information from victims. The actor's primary activities appear to involve deploying this malware to infiltrate systems, with a focus on data exfiltration.

Goals & Targeting

Hagga's strategic objectives appear to center around financial gain through the theft of sensitive financial information and credentials, which could be used for fraudulent transactions or sold on the dark web. The targeting profile suggests a focus on individuals or organizations with accessible financial data, though specific sectors or countries targeted are not definitively known.

Enhanced Description

Hagga is believed to have emerged in the latter half of 2021, employing Agent Tesla—a prolific banking Trojan—in their operations. This malware primarily targets financial information and credentials, indicating that Hagga likely focuses on sectors where such data holds significant value, possibly including the financial sector and retail industries. Agent Tesla's deployment suggests a focus on phishing or social engineering tactics to infect systems, followed by stealthy information theft.

Key Capabilities

  • Information stealing via malware deployment
  • Phishing campaigns to distribute malicious payloads
  • Persistence mechanisms for long-term access
  • Credential theft and unauthorized financial transactions

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Data Exfiltration

ATT&CK Techniques

T1566.003
T1059.002
T1055
T1566.001

Software / Tooling

Agent Tesla

Campaigns & Victims

Hagga's campaigns are ongoing and appear to be associated with the use of Agent Tesla since late 2021. Specific campaign details, including targeted sectors or countries, remain unclear due to limited available intelligence.

IOC Patterns

  • Use of phishing emails containing malicious links
  • Distribution of malware via social engineering tactics

Recommended Actions

  • Implement rigorous user training on phishing detection
  • Enhance network monitoring for suspicious activities
  • Apply endpoint detection and response solutions to identify and mitigate Agent Tesla-like activity

Suggested Tags

APT
cyber_crime
malware

Confidence Assessment

Low confidence due to limited information on primary motivation, attack patterns beyond malware usage, targeted sectors, and specific campaigns. Further intelligence is needed to confirm targeting preferences and operational tactics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
cyber_crime
malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.