Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsA November 2023 Agent Tesla sample used an unusual email attachment—“Purchase Order pdf.zpaq”—to deliver malware through several stages. G DATA analyst Anna Lvova reported that the 6 KB archive expanded into a 1 GB .NET executable, which downloaded and decrypted a disguised payload. The delivery format stood out, but G DATA said the malware’s capabilities were not significantly new. The analysis describes one sample, not evidence that the same campaign is active today or how many people it infected.
What is Agent Tesla malware?
Agent Tesla is Windows malware written for .NET. MITRE ATT&CK has tracked the family since at least 2014 and lists family-level behaviors that include spearphishing attachments, credential theft, keylogging, screenshot capture and data exfiltration. Those are behaviors associated with the broader malware family; the details below describe what G DATA reported about one sample analyzed in 2023.
G DATA published its analysis on November 20, 2023. It reported that the sample’s delivery method was unusual, but that the malware did not offer significantly new capabilities. The analysis also noted that more than 700 versions of this variant had been observed on VirusTotal since September 30, 2023. That figure refers to observed versions, not victims or infected systems, and does not establish current prevalence.
How did the ZPAQ email attachment deliver the malware?
The attack chain reported by G DATA moved from a purchase-order-themed attachment to a large .NET executable, then to an encrypted file disguised with an audio extension, and finally to the Agent Tesla payload.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Email attachment: The email carried a file named “Purchase Order pdf.zpaq.” Its wording suggested a purchase order and PDF, while the actual file extension was ZPAQ.
- Archive extraction: G DATA reported that the 6 KB archive expanded into a 1 GB .NET executable. About 90% of that analyzed executable consisted of zero bytes. The analyst assessed that this bloating could make automated uploading and scanning more difficult; it is a property of this sample, not a general feature of ZPAQ archives.
- Download and decryption: The executable downloaded a file ending in
.wavand decrypted it using 3DES. Despite the audio-like extension, G DATA described the file as camouflage rather than an ordinary audio file. - Payload execution: The final Agent Tesla payload was obfuscated with .NET Reactor. G DATA reported Telegram use for command and control (C2), but Lvova could not retrieve the bot details because of authorization problems.
G DATA also mentioned FTP and SMTP as communication methods seen in similar samples. It did not establish those protocols as communication methods for this specific analyzed payload.
Why was ZPAQ unusual in this attack?
ZPAQ is a compression format that G DATA describes as offering a better compression ratio and a journaling function compared with common ZIP and RAR formats. Its software support is limited: the report says it is primarily extracted with a command-line tool, although graphical unpackers such as PeaZip are available.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
That relative unfamiliarity made the archive choice notable in this case. It does not make ZPAQ malicious, nor does the report show that ZPAQ is inherently more dangerous than ZIP or RAR. The evidence is about one actor’s use of the format in one analyzed delivery chain.
What data could this Agent Tesla sample steal?
G DATA reported that the sample could steal credentials from popular email clients and target data across around 40 web browsers. The browser count describes the capability observed in the sample analysis—not the number of affected users, infected machines or successful thefts.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
The report also described screen logging, keylogging, system-information gathering and collection of sensitive data associated with VPN tools. These findings are specific to the capabilities G DATA reported for its analyzed sample; they should not be read as a measurement of what happened on victims’ devices.
What is known—and not known—about this case?
The analysis establishes the attachment name, the archive-to-executable size disparity, the staged download and decryption, and the capabilities reported for the sample. It does not establish how many systems were infected, how widespread the technique became, or whether the same campaign remains active today. Lvova suggested that attackers might have been testing an uncommon format or aiming at technically knowledgeable users, but those were hypotheses, not confirmed motives.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How should you handle a suspicious purchase-order attachment?
- Treat an unexpected purchase-order attachment cautiously, especially when its actual file type does not match what the message implies.
- Do not open or extract an attachment merely because its name includes “PDF” or resembles a familiar business document.
- If the message arrived through work, report it using your organization’s security process rather than forwarding it informally or testing the file yourself.
The G DATA analysis does not test or compare security products, so it cannot establish that a particular tool detects this sample.
Quick Recap
Sources
- G DATA Security Blog: Anna Lvova’s November 20, 2023 analysis of the ZPAQ-delivered Agent Tesla sample.
- The Hacker News: Contemporary summary published November 21, 2023.
- MITRE ATT&CK: Agent Tesla (Software S0331), family-level profile last modified April 16, 2025.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

