Skip to content

Agent Tesla

Also known as: AgenTesla, AgentTesla, Negasteal

A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.

Linked Threat Actors

SWEED

C2 Infrastructure

Business50%
Hosting/VPS50%

Last 7 days

Apr 19, 2026
C2 Hosts: 2
Apr 15, 2026
C2 Hosts: 2
Apr 14, 2026
C2 Hosts: 1

Further Reading