Negasteal, also known as Agent Tesla, is a Windows spyware trojan first identified in 2014 and sold through paid subscriptions on cybercriminal underground forums. It is used in information-stealing campaigns and distributed through phishing and spam email, including campaigns using LZH compressed archives. Its developers continually modify the malware to improve evasion.
An observed variant delivered Crysis, also known as Dharma, ransomware through a fileless infection chain. Following phishing-based delivery, it established persistence through Windows startup-folder placement and a registry autorun entry. It attempted to interfere with Windows Defender debugging and disable Windows Defender, then retrieved and decoded the ransomware payload from a public text-hosting service. These ransomware-delivery functions were observed in a particular variant and do not make Negasteal itself a ransomware family.
Negasteal has also appeared as an alternative payload in early TargetCompany-associated infection chains alongside Remcos and Snake Keylogger. It has been distributed through Ukraine-themed spam and identified among prominent malware families involved in information-stealing and banking-malware activity across Asia and the South Pacific.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Payloads of early versions of the ransomware from June 2021 ... could either be TargetComp ransomware, the Remcos backdoor, the Negasteal malware, or the Snake Keylogger malware.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer listed among the top malware families prevalent in Asia and the South Pacific.
Named malware available as an alternative payload in early TargetCompany infection chains. The content does not describe its specific capabilities.
Stealer malware mentioned only in an update note as being spread via spam email.
A spyware trojan offered via paid subscriptions on cybercriminal underground forums. In this campaign it arrived via phishing email, used evasion tactics such as excluding itself from debugging and disabling Windows Defender, established persistence via the startup folder and CurrentVersion\Run, then connected to hastebin to decode and deliver the Crysis/Dharma ransomware payload filelessly.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.