Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 5 actorsExploits 7 CVEs

Agent Tesla

Agent Tesla is a widely used Windows credential-stealing malware family, commonly described in the provided reporting as an infostealer/password stealer and in some cases associated with RAT-like surveillance features. It is frequently distributed through phishing and malspam campaigns, including malicious email attachments, archive-contained script loaders, PDF-linked phishing lures, and multi-stage .NET or script-based delivery chains. It is also delivered by other malware loaders and ecosystems including GULoader and Amadey, and has been observed hosted on services such as Discord CDN. Reported targeting includes business users broadly, with specific campaigns aimed at finance users, organizations in Türkiye’s financial sector, the logistics sector in Asia, and Italian-language business-themed malspam campaigns; India-themed financial and tax lures were also seen on related infrastructure delivering Agent Tesla among other payloads.

Across the supplied content, Agent Tesla is associated with credential theft from browsers, theft of session cookies and autofill data, clipboard theft, keylogging, screenshot capture, username collection, and exfiltration of stolen data. Some reports also state that Agent Tesla can access the victim’s webcam and record video. Exfiltration methods directly mentioned include SMTP, FTP, Telegram, and other channels; one AhnLab-cited sample used SMTP. Multiple reports describe modern Agent Tesla intrusion chains as heavily obfuscated and fileless or memory-resident, using PowerShell, Batch scripts, Base64-encoded commands, LOLBAS execution, rundll32 abuse, in-memory loading, and process hollowing into legitimate processes such as charmap.exe. Additional observed defense-evasion behaviors include anti-debugging, anti-sandbox, anti-VM checks, use of hidden windows via ProcessWindowStyle.Hidden, and creation of hidden folders.

The malware appears repeatedly in commodity cybercrime distribution ecosystems. GULoader has delivered Agent Tesla alongside NetWire, FormBook, NanoCore, Parallax RAT, Lumma, Vidar, and Remcos. Amadey botnet clusters have distributed Agent Tesla together with Lumma Stealer, Vidar Stealer, StealC, Rugmi, PureCrypter, Rhadamanthys Stealer, RedLine Stealer, SmokeLoader, XWorm, and AsyncRAT. Related infrastructure in other campaigns also delivered Phantom Stealer, DarkCloud, MassLogger variants, FormBook, XWorm, and Snake keyloggers.

High-confidence indicators and infrastructure explicitly tied to Agent Tesla in the content include SMTP exfiltration settings from Unit 42 analysis: hosting2[.]ro.hostsailor[.]com:587 with sender packagelog@gtpv[.]online and receiver package@gtpv[.]online; mail[.]gtpv[.]online:587 with sender kings@gtpv[.]online and receiver king@gtpv[.]online; nffplp[.]com:587 with sender airlet@nffplp[.]com and receiver smt.treat@yandex[.]com; and mail[.]iaa-airferight[.]com:25 with sender accounts admin@iaa-airferight[.]com and web@iaa-airferight[.]com. Sample hashes explicitly identified as Agent Tesla-related include SHA-256 ac5fc65ae9500c1107cdd72ae9c271ba9981d22c4d0c632d388b0d8a3acb68f4, 30b7c09af884dfb7e34aa7401431cdabe6ff34983a59bec4c14915438d68d5b0, and 5487845b06180dfb329757254400cb8663bf92f1eca36c5474e9ce3370cadbde. One phishing case identified by VirusTotal labeled the payload as an AgentTesla variant and described it as a credential and clipboard stealer.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

7 CVES
CVE-2017-11882Microsoft Office Equation Editor Remote Code ExecutionExploited in the wild

Instead of relying solely on exploiting unpatched document software as seen in past campaigns that heavily abused known Microsoft Office flaws such as CVE-2017-11882, CVE-2017-0199, and CVE-2018-0802, modern operators are utilizing highly deceptive script-based loaders. | In a recently observed attack, a routine-looking phishing email quietly triggered a full-scale malware compromise, showcasing an advanced Agent Tesla infection chain.

via security online infosecurityonline.info
CVE-2017-0199Microsoft Office/WordPad Remote Code Execution VulnerabilityExploited in the wild

Instead of relying solely on exploiting unpatched document software as seen in past campaigns that heavily abused known Microsoft Office flaws such as CVE-2017-11882, CVE-2017-0199, and CVE-2018-0802, modern operators are utilizing highly deceptive script-based loaders. | In a recently observed attack, a routine-looking phishing email quietly triggered a full-scale malware compromise, showcasing an advanced Agent Tesla infection chain.

via security online infosecurityonline.info
CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEExploited in the wild

Instead of relying solely on exploiting unpatched document software as seen in past campaigns that heavily abused known Microsoft Office flaws such as CVE-2017-11882, CVE-2017-0199, and CVE-2018-0802, modern operators are utilizing highly deceptive script-based loaders. | In a recently observed attack, a routine-looking phishing email quietly triggered a full-scale malware compromise, showcasing an advanced Agent Tesla infection chain.

via security online infosecurityonline.info
CVE-2017-8570Microsoft Office Remote Code Execution VulnerabilityExploited in the wild

Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. | Agent Tesla can collect account information from the victim’s machine. Agent Tesla has used HTTP for C2 communications. Agent Tesla has used SMTP for C2 communications.

via mitre attack websiteattack.mitre.org
CVE-2020-14882Oracle WebLogic Server Console Authentication Bypass and RCE

...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.

via fortinet threat signalfortiguard.fortinet.com
CVE-2023-21716Microsoft Word RTF Heap Corruption Remote Code Execution

Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT

via splunk researchresearch.splunk.com
CVE-2020-14883Oracle WebLogic Server Console RCE via Authentication Bypass Chain

...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.

via fortinet threat signalfortiguard.fortinet.com
THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA2541

beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.

via proofpointproofpoint.com
SilverTerrier

The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).

via bleeping computerbleepingcomputer.com
TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

via group ibgroup-ib.com
8220 Gang

...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.

via fortinet threat signalfortiguard.fortinet.com
RATicate

"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

35 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1566PhishingEvidence5

The user had opened an email 15 minutes before the alert. Subject line: “Outstanding Invoice — Action Required” The attachment? A well-crafted PDF.

T1566.001Spearphishing AttachmentEvidence3

15/06/2026 AgentTesla - spread through five campaigns themed around: ‘Documents’, ‘Invoices’, 'Orders' (two) and ‘Requests’. ... FormBook - spread through two campaigns themed around ‘Payments’ and ‘Requests’.

T1566.002Spearphishing LinkEvidence1

The user clicked. The PDF had a malicious link. It launched Edge with a custom URL that invoked the payload.

Execution

6 techniques
T1059Command and Scripting InterpreterEvidence1

This was classic LOLBAS (Living-Off-the-Land Binaries and Scripts) abuse... msedge.exe └── powershell.exe └── curl.exe └── downloaded.dll └── rundll32.exe

T1059.001PowerShellEvidence2

T1059.001 — PowerShell Execution Malicious script executed via encoded PowerShell commands.

T1059.003Windows Command ShellEvidence1

When the attached archive is extracted and opened, the heavily obfuscated Batch script springs into action.

T1129Shared ModulesEvidence1

Upon execution, these files kick off a multi-stage chain of extracting, deobfuscating, loading and executing secondary payloads (dynamic-link libraries), eventually detonating the final payload (executable).

T1204User ExecutionEvidence1

When the attached archive is extracted and opened, the heavily obfuscated Batch script springs into action.

T1204.002Malicious FileEvidence3

The top-ranking samples this week are Script files accounting for 65,22%. MSIL files follow in second place with 20,65%. As for third place, we find Office documents (Word, Excel, PowerPoint) with 14,13%.

Privilege Escalation

2 techniques
T1055Process InjectionEvidence1

Process injection is a critical phase of this operation. By forcing a trusted application like charmap.exe to run the malicious code...

T1055.012Process HollowingEvidence1

This technique, known as process hollowing, involves creating a new instance of the legitimate process in a suspended state, unmapping its original code, and injecting the malicious payload before resuming the process thread.

Stealth

13 techniques
T1027Obfuscated Files or InformationEvidence1

They now employ heavily obfuscated scripts... When the attached archive is extracted and opened, the heavily obfuscated Batch script springs into action.

T1027.003SteganographyEvidence1

This article highlights a new obfuscation technique threat actors are using to hide malware through steganography within bitmap resources embedded in otherwise benign 32-bit .NET applications.

T1055Process InjectionEvidence1

Process injection is a critical phase of this operation. By forcing a trusted application like charmap.exe to run the malicious code...

T1055.012Process HollowingEvidence1

This technique, known as process hollowing, involves creating a new instance of the legitimate process in a suspended state, unmapping its original code, and injecting the malicious payload before resuming the process thread.

T1140Deobfuscate/Decode Files or InformationEvidence2

The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.

T1218System Binary Proxy ExecutionEvidence1

This was classic LOLBAS (Living-Off-the-Land Binaries and Scripts) abuse... msedge.exe └── powershell.exe └── curl.exe └── downloaded.dll └── rundll32.exe

T1218.011Rundll32Evidence1

T1218.011 — Rundll32 Execution Abused rundll32.exe to stealthily execute the malicious DLL.

T1497Virtualization/Sandbox EvasionEvidence1

Furthermore, the payload actively performs anti-sandbox DLL checks and enumerates system hardware to identify virtual machines (Anti-VM). If the code detects artifacts commonly associated with automated malware analysis systems... it abruptly halts execution.

T1497.001System ChecksEvidence1

...enumerates system hardware to identify virtual machines (Anti-VM).

T1564.001Hidden Files and DirectoriesEvidence1

Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.

T1564.003Hidden WindowEvidence1

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden. APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1620Reflective Code LoadingEvidence1

By operating directly in memory, the malware avoids leaving recognizable artifacts on the hard drive... PowerShell, which then pulls and executes additional malicious code directly in memory.

T1622Debugger EvasionEvidence1

Analysts discovered specific anti-debugging functions intended to detect whether the malware is being executed within a controlled debugging environment.

Credential Access

4 techniques
T1056.001KeyloggingEvidence2

Additionally, it features a persistent keylogger that records every keystroke, ensuring that even newly typed passwords are captured.

T1539Steal Web Session CookieEvidence1

It aggressively targets sensitive information, sweeping the compromised system to steal browser credentials, session cookies, and saved auto-fill data.

T1555Credentials from Password StoresEvidence1

It aggressively targets sensitive information, sweeping the compromised system to steal browser credentials...

T1555.003Credentials from Web BrowsersEvidence1

Beyond that, it steals stored credentials and cookies from Chrome and Firefox

Discovery

5 techniques
T1016System Network Configuration DiscoveryEvidence1

The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.

T1033System Owner/User DiscoveryEvidence1

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.

T1497Virtualization/Sandbox EvasionEvidence1

Furthermore, the payload actively performs anti-sandbox DLL checks and enumerates system hardware to identify virtual machines (Anti-VM). If the code detects artifacts commonly associated with automated malware analysis systems... it abruptly halts execution.

T1497.001System ChecksEvidence1

...enumerates system hardware to identify virtual machines (Anti-VM).

T1622Debugger EvasionEvidence1

Analysts discovered specific anti-debugging functions intended to detect whether the malware is being executed within a controlled debugging environment.

Collection

4 techniques
T1056.001KeyloggingEvidence2

Additionally, it features a persistent keylogger that records every keystroke, ensuring that even newly typed passwords are captured.

T1113Screen CaptureEvidence1

The malware frequently captures screenshots of the active desktop, providing the attackers with real-time visual context of the victim’s activities.

T1115Clipboard DataEvidence1

Agent Tesla can steal data from the victim’s clipboard. APT38 used a Trojan called KEYLIME to collect data from the clipboard. APT39 has used tools capable of stealing contents of the clipboard.

T1125Video CaptureEvidence1

Agent Tesla can access the victim’s webcam and record video. AsyncRAT can record screen content on targeted systems. Bandook has modules that are capable of capturing video from a victim's webcam. ... ZxShell has a command to perform video device spying.

Command and Control

2 techniques
T1071.001Web ProtocolsEvidence1

The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."

T1105Ingress Tool TransferEvidence3

First, we see a call to a location in the stack ... that will execute the function InternetOpenUrlA, we also see the C2 it will use... the second shellcode downloads further malware.

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence1

T1041 — Exfiltration Over C2 Channel Data was exfiltrated to an external C2 over HTTPS.

T1048Exfiltration Over Alternative ProtocolEvidence3

AgentTesla can transmit data via FTP, Telegram, SMTP, and other methods; this particular sample used SMTP.

INDICATORS OF COMPROMISE

IOCs tracked for this family

845 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
62 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
84 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
699 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 day ago
ip.v4●●●●●●●●●●●●View more in app5 days ago
ip.v4●●●●●●●●●●●●View more in app5 days ago
domain●●●●●●●●●●●●View more in app11 days ago
domain●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching845

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities7

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping35

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.