Agent Tesla is a .NET-based Windows information stealer and credential-stealing trojan widely used in commodity-malware operations. It targets credentials and associated data from Chromium- and Mozilla-based browsers, email clients, messaging applications, Windows Credential Manager, and other applications. Agent Tesla variants also include keylogging, clipboard-capture, and screen-capture functionality, although individual campaigns may disable particular collection features. Collected information has been exfiltrated through FTP and Discord-based infrastructure.
Agent Tesla is frequently distributed through malspam and business email compromise-themed phishing, including invoice, payment, reservation, request, and order lures. Observed campaigns have targeted Italian organizations and finance personnel. Recent version 4 activity used a Unicode-character-obfuscated JScript attachment and in-memory .NET execution to evade signature- and file-based defenses. Agent Tesla variants employ .NET obfuscation, misleading application metadata, debugger detection, virtual-machine and hosted-environment checks, and security-tool checks. The malware has also been observed accessing browser credential stores and Windows Credential Manager data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These emails typically contain Microsoft Excel spreadsheets or Microsoft Word documents that leverage CVE-2017-11882, a vulnerability affecting Microsoft Equation Editor. When opened by victims, these malicious documents function as malware downloaders.
EML delivers a malicious XLS file; the XLS exploits CVE-2017-0199 to download an HTA script, which then downloads a steganographic image, decrypts and memory-executes a loader, and the loader ultimately executes the AgentTesla family for email-based C2 communication. | After a successful compromise, the group deploys mature remote access trojans and information stealers such as AgentTesla and XWorm on victim endpoints... The two samples analyzed below use AgentTesla and XWorm respectively for command-and-control communication.
Document.doc implements a second exploit in the chain identified by the following CVEs: CVE-2018-0802, CVE-2017-11882, a memory corruption vulnerability. The content of this new document automatically replaces the content of the original document. While Patches already exist for those vulnerabilities, many endpoints were still unpatched due to operational constraints. | The Agent Tesla information stealer has been around since 2014... The final payload that runs within the RegAsm is the main Agent Tesla Dark Stealer module
A full spectrum of payload delivery mechanisms are seen being employed by the maldocs, including links, macros, DDE commands and Office exploits (e.g. CVE-2017-11882 and CVE-2017-8570). | First seen in 2014, AgentTesla is a .NET platformed stealer that has recently surpassed Emotet and Trickbot to become one of the most prevalent malware threats.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
March 2020 Campaign: 동쪽의일어나는행동 (The Rising Action of The East) ... Observed commodity malware: Agent Tesla and Mirai bot.
After a successful compromise, the group deploys mature remote access trojans and information stealers such as AgentTesla and XWorm on victim endpoints... The two samples analyzed below use AgentTesla and XWorm respectively for command-and-control communication.
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
In this campaign, malicious PowerPoint Add-in files were used to deliver Agent Tesla and PowerShell cryptocurrency-stealing malware.
Final Payload – Agent Tesla: Below figure shows injected Agent Tesla payload in RegAsm.exe. Agent Tesla is a well-known keylogger and infostealer written in DotNet.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
The extracted VBA script... downloads and executes a malicious powershell script... additional powershell script blocks... set up persistence, bypass AMSI, disable Windows Defender and create a mechanism to update the malware.
The extracted VBA script... downloads and executes a malicious powershell script.
The attached JScript file is packed with hearts, water droplets and other Unicode emoji characters inserted through its code.
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
The malicious PowerShell script is obfuscated using string substitution to evade detection... The custom DOTNET loader... [uses] dead instruction, renamed symbols... and encoded strings.
The sample we analyzed was heavily obfuscated, masqueraded as an AVG installer,and leverages discord for C2.
“The main payload... injects it into a subprocess. The payload itself stays in memory.”
The custom DOTNET loader... inject[s] a payload into a signed microsoft binary via process hollowing... starts a process in a suspended state... unmap[s] the memory of the target process, writes the payload... and then resume[s] the thread.
The malware starts by deleting the original Word document, first killing the process Winword.exe and then deleting all .DOCX files located in the default Downloads and Desktop folders of every user.
Before stealing information, Agent Tesla checks whether it is running under a debugger, in a cloud-hosted environment or inside a virtual machine. It also looks for software associated with analysis.
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
Once active, it targets logins from 27 Chromium-based browsers and 13 Mozilla-based browsers, along with Outlook, Foxmail, Discord, Thunderbird contacts and Windows Credential Manager.
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
1,523 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload explicitly identified as delivered by DarkTortilla; characterized in the content as an information stealer and remote-access trojan.
A password-stealer family observed in malspam campaigns targeting Italy during the reporting week.
Password-stealing malware distributed through an Italian malspam campaign themed around reservations.
A password-stealing malware family distributed through Italian-language malspam campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.