Agent Tesla is a .NET-based Windows information stealer commonly distributed through phishing and malspam campaigns using business-oriented lures such as payments, invoices, reservations, and requests. It is frequently delivered in malicious attachments, including scripts, archives, Office documents, and OneNote files. Recent variants have used Unicode-character-obfuscated JScript droppers, in-memory execution, reflective loading, and anti-debugging, virtual-machine, cloud-environment, and security-tool checks to hinder analysis and evade file-based detection.
The malware steals credentials and related data from web browsers, email clients, FTP software, messaging applications, and Windows Credential Manager. Agent Tesla has keylogging, clipboard-capture, and screen-capture functionality, although individual samples may selectively disable features through configuration. It can collect running-process information, establish persistence through Windows Registry Run entries, inject or hollow processes, fingerprint compromised hosts, and exfiltrate collected data through FTP, SMTP, or Telegram.
Agent Tesla is commodity malware used by multiple financially motivated threat actors. TA558, also known as SteganoAmor, has deployed it in phishing operations against organizations in Latin America and other regions, including hospitality, finance, government, energy, education, IT, pharmaceutical, and transportation sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
EML delivers a malicious XLS file; the XLS exploits CVE-2017-0199 to download an HTA script, which then downloads a steganographic image, decrypts and memory-executes a loader, and the loader ultimately executes the AgentTesla family for email-based C2 communication. | After a successful compromise, the group deploys mature remote access trojans and information stealers such as AgentTesla and XWorm on victim endpoints... The two samples analyzed below use AgentTesla and XWorm respectively for command-and-control communication.
The malicious spam messages were crafted to exploit CVE-2017-11882. The remote code execution flaw is specific to Microsoft Word Equation Editor. Once exploited, the Warzone RAT payload is downloaded and installed.
Document.doc implements a second exploit in the chain identified by the following CVEs: CVE-2018-0802, CVE-2017-11882, a memory corruption vulnerability. The content of this new document automatically replaces the content of the original document. While Patches already exist for those vulnerabilities, many endpoints were still unpatched due to operational constraints. | The Agent Tesla information stealer has been around since 2014... The final payload that runs within the RegAsm is the main Agent Tesla Dark Stealer module
A full spectrum of payload delivery mechanisms are seen being employed by the maldocs, including links, macros, DDE commands and Office exploits (e.g. CVE-2017-11882 and CVE-2017-8570). | First seen in 2014, AgentTesla is a .NET platformed stealer that has recently surpassed Emotet and Trickbot to become one of the most prevalent malware threats.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
March 2020 Campaign: 동쪽의일어나는행동 (The Rising Action of The East) ... Observed commodity malware: Agent Tesla and Mirai bot.
After a successful compromise, the group deploys mature remote access trojans and information stealers such as AgentTesla and XWorm on victim endpoints... The two samples analyzed below use AgentTesla and XWorm respectively for command-and-control communication.
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
In this campaign, malicious PowerPoint Add-in files were used to deliver Agent Tesla and PowerShell cryptocurrency-stealing malware.
Final Payload – Agent Tesla: Below figure shows injected Agent Tesla payload in RegAsm.exe. Agent Tesla is a well-known keylogger and infostealer written in DotNet.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The attached JScript file is packed with hearts, water droplets and other Unicode emoji characters inserted through its code.
The attached JScript file is packed with hearts, water droplets and other Unicode emoji characters inserted through its code. Windows Script Host ignores those characters when it parses the script, but the visual clutter can frustrate quick reviews and weaken simple text-based detection rules.
The final payload presents itself as a Python installer in its program information, although analysts found a 32-bit .NET 4.0 binary instead.
Once executed, the malware injects its payload directly into memory, preventing detection by file-based scanners.
Before stealing information, Agent Tesla checks whether it is running under a debugger, in a cloud-hosted environment or inside a virtual machine. It also looks for software associated with analysis.
Before stealing information, Agent Tesla checks whether it is running under a debugger, in a cloud-hosted environment or inside a virtual machine. It also looks for software associated with analysis.
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
Once active, it targets logins from 27 Chromium-based browsers and 13 Mozilla-based browsers, along with Outlook, Foxmail, Discord, Thunderbird contacts and Windows Credential Manager.
Before stealing information, Agent Tesla checks whether it is running under a debugger, in a cloud-hosted environment or inside a virtual machine. It also looks for software associated with analysis.
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
1,520 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A password-stealing malware family distributed through Italian-language malspam campaigns.
AgentTesla appeared in the weekly campaign breakdown as malware distributed via malspam themes such as payments and reservations in Italian-targeted campaigns.
Agent Tesla is an infostealer used to steal user credentials. In this campaign, version 4 is delivered via BEC attacks, uses a JScript dropper with embedded Unicode emoji characters for obfuscation, injects its payload into memory to evade file-based detection, employs ConfuserEx obfuscation, disguises itself as a Python installer, performs debugger detection, fingerprints hardware for persistent tracking, harvests credentials from over 40 applications, and exfiltrates data to an attacker-controlled FTP server.
Credential-stealing malware delivered via a Unicode-obfuscated JScript dropper in a BEC-themed phishing campaign. It steals browser, email, messaging, and Windows credentials; can also perform keylogging, clipboard capture, and screen capture; uses anti-debugging/anti-VM checks; and exfiltrates data over FTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.