Agent Tesla
MITRE ATT&CK: S0331 View on attack.mitre.org
Aliases: AgenTesla, AgentTesla, Negasteal, Agent Tesla
- First seen
- 2014-01-01 00:00:00
- Malware type
- spyware, trojan, credential-stealer, keylogger, screen-capture
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 24447 (23752 malicious)
- Last IoC activity
- 2026-09-02 03:45:05
- Profile updated
- 2026-07-07 12:37:53
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector retail-and-hospitality transportation-and-logistics
Context
Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.
Recent IoC activity
23,764 malicious indicators in Maltiverse are attributed to Agent Tesla (S0331). The 20 most recently updated:
Detection coverage
- 6 YARA rules
- 818 Sigma rules
Malware & tools used
- Process Injection (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Clipboard Data (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Screen Capture (attack-pattern)
- Local Account (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Credentials In Files (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Malicious File (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Regsvcs/Regasm (attack-pattern)
- System Time Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Process Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Video Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Browser Session Hijacking (attack-pattern)
- Web Protocols (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Hidden Window (attack-pattern)
- Keylogging (attack-pattern)
Used by threat actors
- TA2536 (threat-actor)
- SilverTerrier (threat-actor)
- TA2541 (threat-actor)
Exploited vulnerabilities
- CVE-2023-38831 (vulnerability)
Detection rules
- COD3NYM_SUSP_OBF_NET_Reactor_Native_Stub_Jan24 (yara-rule)
- CAPE_Agentteslav4Jit (yara-rule)
- CAPE_Agentteslav3Jit (yara-rule)
- CAPE_Agent_Tesla (yara-rule)
- CAPE_Agenttesla (yara-rule)
- CAPE_Agentteslav4 (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Cisco Talos — Sweed Agent Tesla (report)
- secureworks.com — Gold Galleon How A Nigerian Cyber Crew Plunders The Shipping Industry (report)
- secureworks.com — Gold Galleon (report)
- proofpoint.com — Dtpacker Net Packer Curious Password 1 (report)
- team-cymru.com — An Analysis Of Infrastructure Linked To The Hagga Threat Actor (report)
- research.checkpoint.com — Agent Tesla Targeting United States And Australia (report)
- CISA — Aa20 345A (report)
- blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
- checkpoint.com — March 2022S Most Wanted Malware Easter Phishing Scams Help Emotet Assert Its Dominance (report)
- ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
- Cisco Talos — 2020 Year In Malware (report)
- cisecurity.org — Top 10 Malware March 2022 (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- lac.co.jp — 20220307 002893 (report)
- cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
- proofpoint.com — New Whiteshadow Downloader Uses Microsoft Sql Retrieve Malware (report)
- bitsight.com — Exfiltration Over Telegram Bots Skidding Infostealer Logs (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- malwarebytes.com — 20221121 Threat Intel Report Final (report)
- securityintelligence.com — Roboski Global Recovery Automation (report)
- blog.netlab.360.com — Purecrypter (report)
- securityintelligence.com — Spam Trends Campaigns Senior Superlatives 2023 (report)
External references
- mitre-attack — S0331
- Agent Tesla
- Bitdefender Agent Tesla April 2020
- Talos Agent Tesla Oct 2018
- Malwarebytes Agent Tesla April 2020
- DigiTrust Agent Tesla Jan 2017
- Fortinet Agent Tesla April 2018
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy