Agent Tesla, also referred to as Negasteal, is a long-running commodity spyware and information-stealing malware family active since at least 2014 and commonly sold through subscription-based criminal markets. It is widely used in financially motivated campaigns and has appeared in spam-driven operations as well as broader cybercrime activity affecting multiple regions.
The malware is primarily associated with credential and information theft on Windows systems. Reported campaigns show it being delivered through phishing emails and spam messages, including archive-based attachments and lure themes tied to current events or business communications. In one observed intrusion chain, an Agent Tesla variant was used as an initial-stage malware component that established persistence, attempted to weaken Microsoft Defender protections, and then retrieved and decoded a Dharma/Crysis ransomware payload for fileless execution. This demonstrated that the malware can be combined with other criminal tooling beyond standalone espionage or theft.
Observed behaviors include persistence via common autorun mechanisms, defense evasion through attempts to disable or exclude itself from security controls, and post-compromise retrieval of additional payloads. Its operators and developers have repeatedly modified the malware to improve evasion and operational effectiveness. Agent Tesla has also been cited among the more prevalent information-stealing malware families in cybercrime reporting for Asia and the South Pacific.
Overall, Agent Tesla is best characterized as a commodity Windows infostealer/spyware platform frequently distributed through email-based social engineering and adaptable enough to support follow-on malware delivery, including ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer listed among the top malware families prevalent in Asia and the South Pacific.
Stealer malware mentioned only in an update note as being spread via spam email.
A spyware trojan offered via paid subscriptions on cybercriminal underground forums. In this campaign it arrived via phishing email, used evasion tactics such as excluding itself from debugging and disabling Windows Defender, established persistence via the startup folder and CurrentVersion\Run, then connected to hastebin to decode and deliver the Crysis/Dharma ransomware payload filelessly.
Mentioned as another malware family previously delivered via LZH archives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.