Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 18 hostnames
Agent Tesla is a long-running .NET-based credential-stealing malware family that has been active since 2014 and is widely sold and abused in commodity cybercrime operations.
Profile source: Mallory opens in a new tabAgent Tesla
Agent Tesla is a long-running .NET-based credential-stealing malware family that has been active since 2014 and is widely sold and abused in commodity cybercrime operations. It is commonly characterized as spyware or a keylogger with remote-access functionality, and is frequently used to steal sensitive user data from Windows systems. Reported capabilities include keylogging, clipboard capture, screen capture, theft of stored browser and email credentials, and exfiltration of collected information, including via SMTP and in some cases Telegram-based infrastructure.
Agent Tesla is routinely distributed through phishing and malspam campaigns using business-themed lures such as orders, requests, quotations, invoices, offers, shipping, payment, and tax-related themes. Delivery has been observed through compressed attachments, malicious Office documents, script-based loaders, executable payloads, and archive-delivered multi-stage infection chains. It has also been delivered through fake landing pages and through obfuscated loader ecosystems such as Cruciferra and Lua or AutoIt-based fileless chains including the TTF Trap campaign. Exploitation of older Microsoft Office vulnerabilities including CVE-2017-11882 and CVE-2017-8570 has also been associated with Agent Tesla delivery.
The malware remains prevalent in broad, opportunistic campaigns as well as sector-focused operations. Observed targeting has included enterprises and individual users, with campaigns affecting finance, healthcare, government, education, manufacturing, hospitality, travel, and corporate finance functions, as well as regional targeting in countries such as Italy and India. Agent Tesla is often clustered with other commodity malware families such as FormBook, Remcos, XWorm, AsyncRAT, Snake Keylogger, and XLoader, reflecting its role in the commodity malware ecosystem rather than exclusive use by a single threat actor. It has also appeared as a payload in campaigns linked to shared criminal delivery infrastructure used by multiple unrelated actors.
C2 tracking
Derp observations, rolling seven-day window
Samples
21871794d9b51b04698daa0385a36d0092ba26aabd0da5e3106c5fa102adb703 620b824bc1426bd64f3c0ce6fad30fb38d50a411dc70429964ed8ca65b0ff5ce 717367b26afe81de1a41fe61ca58434b7334efa2e83bc11d40f2ec319da6c992 857366a03fe78721ac6828fb2ddd5e1ba3ed79b9ca73e243db776bb5c5de4bf1 cfbe43d4ecedf955f8aad7dc2f56969a791adfebebfe464b74d15ac694b32210 06d7286fe48d9ab8724fdd4049e62d9fc525a5ce3898a9df6ca6afe27dbbd2b5 0a71bbd1903835fcbcb323179b460238184a4b406a3f3eab7341b0b003a26b6a 2b7b0c17cc188411550d3e1d60cd98ff982fb649ce4694b4c72d53597f593916 450b6c8ffce56ab8cb90010bdcfd25b20433ab6a2383785090d300b1f352bd9f 60b6d33f3c8e7321b712489c201910042b3f082e93ecba0fabb25ec1718c706b Reported operators
[π½TA] TA558 (π΄): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.
The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."
Exploited software
MITRE ATT&CK
Reporting
Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.
A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Researchers reported a large-scale phishing campaign targeting Windows users with malicious archives that masquerade as business cooperation or payment-related documents from well-known companies. The infection chain uses heavily obfuscated JScript droppers and an AutoIt- or Lua-based loader disguised as a TrueType font (.ttf) file, enabling a largely fileless compromise path designed to avoid detection. Security reporting described the operation as global in scope, with lures crafted to persuade recipients to open fake font files that trigger the malware delivery process. The campaign has deployed multiple commodity malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, the latter assessed as a variant of Snake Keylogger based on shared modules and coding patterns. Researchers said the loader evolved significantly from late 2025 through mid-2026, adding anti-analysis features such as junk code, string obfuscation, API unhooking, breakpoint neutralization, Donut shellcode signature patching, decoy memory, and segmented shellcode decryption through a Vectored Exception Handler. Published indicators include domains, IP addresses, a Discord-hosted malicious JavaScript file, and SHA-256 hashes to support enterprise detection and threat hunting.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.