Agent Tesla is a .NET-based information stealer and keylogger targeting Windows systems, distributed commercially through malware-as-a-service arrangements. It steals saved credentials and browser data from web browsers, email clients, FTP applications, VPN clients, messaging applications, and wireless profiles. Analyzed variants support credential extraction from more than 80 applications, collection of Thunderbird email contacts, keyboard and clipboard monitoring, and gathering of operating-system, hardware, and user information. Feature activation varies between builds; some variants disable keylogging, screenshot, clipboard, and cookie collection. Stolen information is exfiltrated through SMTP, FTP, or attacker-controlled Telegram bots.
Its primary distribution mechanism is phishing email, including bulk spam and targeted spearphishing with invoice, purchase-order, payment, quotation, and shipping lures. Payloads arrive through malicious Office documents and archive attachments containing disguised Windows executables. Delivery campaigns have exploited Microsoft Office vulnerabilities CVE-2017-0199, CVE-2017-11882, and CVE-2018-0802, as well as WinRAR vulnerability CVE-2023-38831. Multistage infection chains use obfuscated scripts, PowerShell, image-embedded encoded payloads, and memory-loaded .NET components. Agent Tesla supports process injection, and delivery loaders have used process hollowing to execute it inside legitimate Windows processes. Analyzed payloads employ code obfuscation and checks for debuggers, security software, virtual machines, sandboxes, and hosting environments, terminating when analysis conditions are detected.
Agent Tesla has been used by multiple independent cybercriminal actors, including TA558, operators tracked under SilverTerrier, Fucosreal, and OPERA1ER. Campaigns have targeted maritime organizations, manufacturing enterprises, government institutions, banks, healthcare-related organizations, and international trading businesses. Its broad availability and use across unrelated campaigns distinguish it from malware tied exclusively to a single threat actor or geographic region.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Excel document is in OLE format with crafted embedded data that exploits the CVE-2017-0199 vulnerability. It contains an embedded OLE hyperlink, which is opened automatically once the Excel document is started by the victim.
The RTF document has embedded malicious code. It Leverages the Equation Editor Vulnerability (CVE-2017-11882) to trigger the download of the subsequent payloads in the attack chain. The process utilizes the legitimate executable “EQNEDT32.EXE” to initiate the execution of malicious shellcode.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
The malicious attachment is, in fact, an RTF document exploiting the CVE - 2018-0802 vulnerability. When accessed it will prompt the download of Agent Tesla Malware to the victim’s machine.
Rapid7 is responding to various compromises arising from the exploitation of CVE-2022-47966, a pre-authentication remote code execution (RCE) vulnerability impacting at least 24 on-premise ManageEngine products. CVE-2022-47966 stems from a vulnerable third-party dependency on Apache Santuario.
A full spectrum of payload delivery mechanisms are seen being employed by the maldocs, including links, macros, DDE commands and Office exploits (e.g. CVE-2017-11882 and CVE-2017-8570). | First seen in 2014, AgentTesla is a .NET platformed stealer that has recently surpassed Emotet and Trickbot to become one of the most prevalent malware threats.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Per the research and analysis blog by Cyren, this sample downloads and installs AgentTesla malware.”
“In March 2024, we discovered a spam campaign targeting our clients which distributed a malicious TAR archive ... This archive contained the Agent Tesla stealer.”
Большинство изученных писем содержали вредоносное программное обеспечение (ВПО) Agent Tesla или Remcos, относящееся к классу Remote Administration Tools (RAT).
“Malware: ... Sherlock, AgentTesla, Remcos, Neutrino, BlackNET, Venom RAT.”
In May 2024, bukky101 delivered a sample of Agent Tesla ... The data was exfiltrated via the attacker's SMTP server at boydjackson[.]org.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon exploiting the successful vulnerability, it leads to BAT file execution, which pretends to be a PDF file.
1,583 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer delivered in emails posing as business and quotation requests from an Indian plumbing company; it uses SMTP to exfiltrate stolen information.
A password-stealing malware family distributed via Italian malspam campaigns during the reporting period.
A password-stealing malware family distributed through malspam campaigns targeting Italy during the reporting week.
A payload explicitly identified as delivered by DarkTortilla; characterized in the content as an information stealer and remote-access trojan.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.