Palo Alto Networks Unit 42 reported that OriginLogger emerged as a commoditized successor to Agent Tesla after that malware operation shut down in 2019, carrying forward much of the same code and behavior while introducing distinct builder artifacts, infrastructure, and configuration patterns. The malware functions as an information stealer and keylogger, with exfiltration observed over SMTP, FTP, web panels, and Telegram bots, giving operators multiple channels to collect stolen data from infected systems.
The research tied OriginLogger activity to infrastructure including originpro[.]me and originlogger[.]com, and documented a real-world dropper chain used to deliver the malware. By extracting 1,917 configurations, investigators identified recurring web panels, authentication infrastructure, obfuscated configuration storage methods, and Telegram bot naming conventions that helped cluster samples and distinguish OriginLogger from its Agent Tesla predecessor.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Bitsight reported that between October and December 2023, at least 5,300 computers were compromised across about 210 observed AgentTesla/OriginLogger campaigns. The telemetry indicated the United States was the most targeted country, followed by China and Germany.
A newer OriginLogger builder was compiled on June 29, 2022 and authenticated over TCP port 3345 to 23.106.223[.]46.
A VirusTotal search for the builder’s default SmartWords string matched a file with SHA256 595a7ea981a3948c4f387a5a6af54a70a41dd604685c72cbd2a55880c2b702ed uploaded on May 17, 2022.
Beginning around March 7, 2022, the domain 0xfd3[.]com resolved to 23.106.223[.]47. The same domain also had DNS MX and TXT records for mail.originlogger[.]com.
Since March 3, 2022, IP address 23.106.223[.]46 has resolved to originpro[.]me, tying that host to OriginLogger authentication infrastructure.
An older OriginLogger builder analyzed by the researcher was compiled on September 6, 2020 and attempted to authenticate with 74.118.138[.]76.
On March 4, 2019, Agent Tesla shut down due to legal troubles. Its developers then suggested in a Discord announcement that users switch to OriginLogger.
A 2018 YouTube video promoted OriginLogger as a “fully undetectable” malware product and showed its web panel and builder, indicating the malware was being marketed publicly by that year.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
bitsight.com
Open sourceunit42.paloaltonetworks.com
Open sourcenews.sophos.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.