Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2 / Distribution
- Host form
- 30 IP / 44 hostnames
Agent Tesla is a .NET-based Windows information stealer and credential-stealing trojan widely distributed as commodity malware.
Profile source: Mallory opens in a new tabAgent Tesla
Agent Tesla is a .NET-based Windows information stealer and credential-stealing trojan widely distributed as commodity malware. It targets credentials and related data held by Chromium- and Mozilla-based browsers, email clients, messaging applications, Windows Credential Manager, and other installed applications. Variants have keylogging, clipboard-capture, and screen-capture functionality, and can exfiltrate collected information through FTP, SMTP, Telegram, Discord, or other attacker-controlled services. Agent Tesla commonly employs obfuscation, misleading application metadata, anti-debugging, virtual-machine and sandbox checks, and in-memory execution to impede detection and analysis. It is frequently delivered through phishing and malspam, including business-themed invoice, reservation, payment, request, and wire-transfer lures. A version 4 campaign used a Unicode-character-obfuscated JScript attachment in business email compromise-style messages targeting finance personnel, then reflectively loaded the final payload in memory. Agent Tesla has affected Windows users and organizations globally, including Italian business targets in recurring malspam activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
20b9236310a2ceaba13684b795dfe3db4281237f1681966422c98066f07c85bb 8c6ff2a22a3f412a6182bcdbed66daf753aca1f84b355ec7c747be3b7a9ea546 926c3d8e5e2dddd788189ece888d503e4d97c65f22b9c00fb4d5c68445aa08b9 9da4eb886a8667cf3277bcfb956f0a43e67fa6f432035069350a528ec05ff943 c9a14a9e0aff3962cb73e48a76d91a3743001e3da6d5376c75b56d8dd02b176f 84b1247feccb737b2b5f34378282431cac74eeec270c2cf5b120b54ef82aa625 85b7ffee9664352f60b0ca40b78f7a1294c9cca3a6f389e9aaa6c1b1244d1f02 e3d8963c5bb44186a85006eefb7650e744d62939d99cd0d27412610b528b1e79 f44905e3daa49b227c0f8509683b71eea01b9648ed5d6404efbd90534f1fe08b fa8fce222bb640d21d36763c893e00d28ecd7e5f5ea7d5976178cd6cdb9aa89f Reported operators
March 2020 Campaign: λμͺ½μμΌμ΄λλνλ (The Rising Action of The East) ... Observed commodity malware: Agent Tesla and Mirai bot.
After a successful compromise, the group deploys mature remote access trojans and information stealers such as AgentTesla and XWorm on victim endpoints... The two samples analyzed below use AgentTesla and XWorm respectively for command-and-control communication.
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
UAC-0041 (AgentTesla, XLoader)
In this campaign, malicious PowerPoint Add-in files were used to deliver Agent Tesla and PowerShell cryptocurrency-stealing malware.
Final Payload β Agent Tesla: Below figure shows injected Agent Tesla payload in RegAsm.exe. Agent Tesla is a well-known keylogger and infostealer written in DotNet.
Final Payload β Agent Tesla: Below figure shows injected Agent Tesla payload in RegAsm.exe. Agent Tesla is a well-known keylogger and infostealer written in DotNet.
beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.
The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
Exploited software
MITRE ATT&CK
Reporting
A new Agent Tesla v4 campaign is targeting finance departments with a business email compromise-style lure that impersonates Metropolitan Bank and Trust Company and presents a forwarded, internal-looking email thread with a malicious attachment. Researchers said the attack chain is designed to look routine to recipients while delivering an infostealer that focuses on credential theft and account compromise. After execution, the malware uses a JScript dropper with novel Unicode emoji-based obfuscation and deploys DonutLoader shellcode for reflective PE injection, allowing the final payload to run in memory without touching disk. Additional evasion features include ConfuserEx obfuscation, misleading metadata, and debugger detection, while the malware steals credentials from more than 40 applications, captures keystrokes and clipboard data, fingerprints infected hosts, and quickly exfiltrates data to an attacker-controlled FTP server; defenders were advised to hunt for emoji Unicode patterns alongside JScript indicators such as WScript.Shell and CreateObject.
Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.
A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.