Agent Tesla continued to appear in phishing-led intrusion chains that used malicious Office documents, ISO attachments, JavaScript, VBScript, and NSIS-based loaders to infect Windows systems and deploy the .NET infostealer in memory. Multiple reports described delivery through macro-enabled purchase-order lures, DHL-themed malspam, and droppers that abused certutil.exe, mshta, and spoofed or cybersquatted infrastructure such as diodetechs[.]com. Researchers also documented layered packing and concealment methods including oversized padded executables, embedded bitmap and PNG resources, reversed payloads, XOR and compression routines, and steganography that hid intermediate DLLs or final payloads inside image files before injection into processes such as MSBuild.exe.
Once installed, Agent Tesla established persistence through Run registry keys, scheduled tasks, Startup-folder entries, or dropped copies under %APPDATA%, then harvested credentials and surveillance data from browsers, Outlook and other email clients, FTP and VPN software, cookies, clipboard contents, keystrokes, screenshots, and in some cases cryptocurrency wallet addresses. Stolen data was exfiltrated over SMTP, FTP, HTTP, and sometimes Tor-backed channels, with some samples checking agenttesla[.]com for updates or using attacker mailboxes embedded in configuration data. Researchers also observed variants paired with additional malware, including a clipboard hijacker and Crysis/Dharma ransomware, underscoring how this long-running malware-as-a-service family combines commodity phishing delivery with evolving obfuscation and post-infection tradecraft.

Pull IOCs and campaign context straight into your stack.
19 events from the most recent confirmed update back to the earliest known activity.
A malware analysis documented an Agent Tesla infection delivered through a 'Purchase Inquiry.gz' email attachment that unpacked a BAT file, launched an obfuscated WSF/JavaScript stage, fetched additional PowerShell content from didaktik-labor.de, and used InstallUtil.exe to run the final EXE. The report said the malware stole credentials and system data from browsers, email, FTP, and VPN applications and exfiltrated data over SMTP to infrastructure tied to mail.knoow.net at 94.237.43.240.
A SANS ISC analysis highlighted a .NET executable captured in October 2021 whose size was inflated to about 300 MB with a null-byte overlay. Further analysis identified it as Agent Tesla infostealer and showed the padding could help evade file-size scanning limits.
VMRay analyzed a recent Agent Tesla v3 sample delivered via an invoice-themed RTF attachment exploiting CVE-2017-11882, then abusing CMSTP.exe and an INF file before installing the payload through process hollowing. The report also highlighted v3-specific capabilities including Telegram exfiltration, optional Tor-backed HTTP communications, clipboard theft, and external IP collection.
An analysis of Agent Tesla described multi-stage .NET loaders using reflection, embedded resources, steganography, and anti-decompiler protections to unpack the final stealer. The report also documented persistence via a scheduled task launching a dropped executable from %APPDATA% at logon.
Multiple references describe Agent Tesla as a malware-as-a-service .NET stealer/RAT first seen in 2014. It later became widely used for credential theft, keylogging, screenshots, and other surveillance functions.
Positive Technologies documented the 'SteganoAmor' campaign, attributing it to TA558 and describing mass attacks against companies and public institutions around the world. The campaign used steganography as part of its delivery chain to distribute Agent Tesla.
A Japanese-language mass phishing campaign used a payment-themed compressed attachment containing a disguised VBScript that fetched code from paste[.]ee, downloaded image-hosted steganographic content, and unpacked a .NET loader. The loader established persistence via C:\ProgramData\Name_File.vbs and the Run key, then injected a final Agent Tesla payload into MSBUILD.exe and exfiltrated stolen data over SMTP to mail[.]privateemail[.]com.
Zscaler ThreatLabZ identified an attack chain using the spoofed domain diodetechs[.]com to imitate Diode Technologies and deliver AgentTesla through malicious Office documents. After notification to the legitimate company, the malicious domain was suspended.
An analysis of a SHA-256-identified NSIS package showed it dropped cwlkewfbz.exe and encrypted files, then used anti-debug timing checks, shellcode, and API hashing to decrypt later stages. The final unpacked .NET stage exposed SMTP-related configuration consistent with Agent Tesla.
A forensic analysis showed a malicious XLSM workbook using Workbook_Open VBA code and certutil.exe to download a .NET loader from 18.179.111[.]240. The loader then fetched a reversed PE payload disguised as a JPG and loaded it in memory as part of an Agent Tesla infection chain.
Qualys analyzed an Agent Tesla sample that used two-stage DLL unpacking, steganography, code injection or process hollowing, and SMTP exfiltration. The report also documented theft of browser, Outlook, FTP, VPN, cookie, clipboard, keystroke, and screenshot data.
An analysis compared a JavaScript downloader that fetched an executable from mudanzasdistintas[.]com.ar with a VBScript dropper that embedded its payload as base64. Both scripts were used to deliver Agent Tesla, but exposed different detection opportunities.
FortiGuard Labs observed a phishing campaign using a malicious Excel attachment to launch VBScript via mshta and deploy a new Agent Tesla variant. The same chain also hijacked copied Bitcoin addresses and replaced them with an attacker-controlled wallet.
A malware analysis blog examined an Agent Tesla sample that stole browser, email, FTP, and system information. During debugging, the malware created a SQLite database with tables used to store harvested credentials and related victim data.
A DHL-themed phishing email spoofing dhl.com delivered an ISO attachment containing a VB.NET executable that unpacked BestFit.dll and PositiveSign.dll. The malware reused code from the legitimate Virus Effect Remover tool to appear more benign.
Proofpoint analyzed the CyaX and Hectobmp .NET packer families, showing they hid malware payloads inside embedded images. The report included multiple samples where the recovered final payload was Agent Tesla.
Trend Micro observed a Negasteal/Agent Tesla variant delivering Crysis/Dharma ransomware through a fileless hastebin-based mechanism. The researchers said this was the first time they had seen Negasteal used with a ransomware payload.
Palo Alto Networks analyzed a packed Agent Tesla sample named one.jpeg.png.exe that was seen in the wild on August 29. The sample used layered .NET obfuscation, zlib decompression, and a PNG resource to unpack a final Agent Tesla payload with decryptable SMTP configuration.
FortiGuard Labs reported a new Agent Tesla variant delivered through a malicious Word document with an auto-executing VBA macro. The chain downloaded javs.exe, injected a second .NET payload into a suspended process, established persistence as JavaUpdtr.exe, and stole credentials, keystrokes, clipboard data, and screenshots.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 214 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
21 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcezscaler.com
Open sourceidanmalihi.com
Open sourceblog.itochuci.co.jp
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.fortinet.com
Open sourcemicrosoft.com
Open sourceptsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.