Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In April 2021, attackers used the name of Abu Dhabi-based Petroham Oil & Gas in a phishing email carrying an Agent Tesla spyware downloader. The available account documents an impersonation and malicious attachment—not a breach of Petroham’s network, or an attack on oil-field, refinery, or pipeline systems.

How did Agent Tesla target an oil and gas company?

Infoblox observed the spam campaign from April 3 to 5, 2021. The sender address was spoofed to look like Petroham Oil & Gas, which Infoblox described as a legitimate Abu Dhabi-based chemical and petrochemical company. The message had the subject line “Labour Day holiday RFQ 191938,” no body text, and an Excel attachment named RFQ 191938.xls. The spreadsheet contained malicious macros. Infoblox’s campaign analysis does not report that Petroham itself was compromised.

What happened when the attachment was opened?

In the sample Infoblox analyzed, opening the spreadsheet produced a misleading Office error while Windows cmd.exe ran a PowerShell script through Windows Management Instrumentation (WMI). The malware created a scheduled task for persistence, then used aspnet_compiler to contact command-and-control infrastructure and download the Agent Tesla payload.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The observed payload captured credentials stored in browsers and the Windows registry, and took screenshots. Those are steps in this reported sample’s infection chain; Agent Tesla campaigns can use different delivery and execution methods.

What is Agent Tesla?

MITRE ATT&CK classifies Agent Tesla as a .NET spyware Trojan that has been observed since at least 2014 and runs on Windows. Its cataloged behaviors include phishing attachments, keylogging, credential collection, screenshots, persistence, and data exfiltration using more than one protocol. MITRE’s page is version 1.3, last modified April 16, 2025.

A separate FortiGuard Labs analysis published February 25, 2026 describes a different Agent Tesla chain: a business-themed email with a RAR attachment, JScript and PowerShell loaders, in-memory execution using process hollowing, credential and cookie collection, and SMTP exfiltration. That account illustrates how the malware’s delivery pipeline can vary; it is not evidence that those steps occurred in the Petroham-themed 2021 campaign. Read the FortiGuard Labs analysis.

Does this mean oil infrastructure was attacked?

No such impact is established by the cited campaign account. It describes a phishing email impersonating an energy-sector company and spyware designed to steal information. It does not report disruption to industrial control systems, operational technology, a refinery, or a pipeline. It also gives no victim count, infection total, or financial-loss estimate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MITRE cites a separate Bitdefender article titled “Oil & Gas Spearphishing Campaigns Drop Agent Tesla Spyware in Advance of Historic OPEC+ Deal,” dated April 21, 2020. Its original URL now redirects to Bitdefender’s general Labs page, so specific claims about that campaign’s victims, location, or impact cannot be confirmed from the accessible article. The cited Bitdefender URL.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can organizations do to reduce this kind of risk?

Infoblox recommends keeping computers and endpoints up to date, treating unexpected attachments and vague emails that prompt action with caution, and filtering email attachments. These measures address different points in the path from delivery to execution; the campaign report provides no comparative effectiveness figures, and no single measure guarantees protection.

  • Keep endpoints patched: Updates reduce exposure to known vulnerabilities, though patching alone does not establish that a malicious attachment is safe.
  • Handle unexpected files cautiously: Verify the sender through a separate trusted channel when a message or attachment is unexpected, especially when it appears to involve a request for quotation or another business process.
  • Filter attachments: Email controls can reduce delivery of malicious files. Infoblox’s direct advice is: “Be cautious of emails from unfamiliar senders and inspect unexpected attachments before opening them.”

FortiGuard’s 2026 article also discusses email security, sandboxing, endpoint detection, and network blocking in relation to its separate campaign. Those are vendor-described controls, not independently tested remedies for the Petroham-themed incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.