Skip to content

Agent Tesla

Agent Tesla is a long-running .NET-based credential-stealing malware family that has been active since at least 2014 and is widely sold and abused in cybercrime operations.

Profile source: Mallory opens in a new tab

Agent Tesla

Family profile

Agent Tesla is a long-running .NET-based credential-stealing malware family that has been active since at least 2014 and is widely sold and abused in cybercrime operations. It is commonly characterized as spyware, a keylogger, and a remote-access-capable stealer, with core functionality centered on harvesting sensitive user data from infected Windows systems. Reported capabilities include keylogging, clipboard capture, screen capture, theft of stored browser and email credentials, and exfiltration of stolen information, including via SMTP in some campaigns. Agent Tesla is frequently grouped with commodity infostealers and password stealers and remains a prevalent tool in opportunistic financially motivated intrusion activity.

Distribution is strongly associated with phishing and malspam. Observed campaigns have used business-themed email lures, compressed attachments, malicious documents, executable payloads, and archive-delivered stages. Agent Tesla has also appeared as a payload delivered by multi-stage loader and crypter ecosystems, including fileless Lua- or AutoIt-based phishing chains and the Cruciferra crypter service, which has been used by multiple unrelated criminal groups to protect and deploy commodity malware. Campaign themes have included invoices, orders, offers, requests, shipping or payment pretexts, tax-related lures, and impersonation of legitimate organizations.

The malware primarily targets Windows environments. It has been observed in broad, global spam and phishing activity rather than narrowly targeted espionage, affecting enterprises and individual users across multiple sectors. Industries repeatedly exposed through campaigns carrying Agent Tesla or its delivery infrastructure include finance, healthcare, government, education, manufacturing, hospitality, and travel. Exploitation of older Microsoft Office vulnerabilities has also been associated with some Agent Tesla delivery activity, reinforcing its role as a durable commodity threat in email-borne intrusion ecosystems.

Capabilities

  • Credential Theft
  • Exfiltration
  • Keylogging

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 24, 2026
Last activity
Jul 31, 2026
Feed role
C2 / Distribution
Host form
5 IP / 28 hostnames

Leading locations

  • US17
  • MY5
  • BG1
  • CH1
  • DE1
  • FR1
  • GB1
  • GR1
  • IN1
  • IT1
  • LV1
  • SE1

Leading providers

  • Cloudflare, Inc.7
  • Amazon.com, Inc.3
  • HostPapa2
  • Network Solutions, LLC2
  • TM TECHNOLOGY SERVICES SDN. BHD.2
  • Belcloud LTD1

Infrastructure traits

  • Hosting 30
  • Anycast 7

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
TA558

[๐Ÿ‘ฝTA] TA558 (๐Ÿด): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)

TA2541

beginning in late 2021, Proofpoint observed this group begin using DiscordApp URLs linking to a compressed file which led to either AgentTesla or Imminent Monitor.

SilverTerrier

The info stealers most popular with SilverTerrier last year were LokiBot (446 unique samples/month), Pony (330 unique samples/month), and Agent Tesla .NET keylogger (95 unique samples/month).

TMT

The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.

8220 Gang

...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.

RATicate

"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."

Exploited software

Vulnerabilities linked to Agent Tesla

7 CVEs

MITRE ATT&CK

Agent Tesla in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1588.001 Malware T1567 Exfiltration Over Web Service T1071.001 Web Protocols T1560 Archive Collected Data T1041 Exfiltration Over C2 Channel T1102.002 Bidirectional Communication T1056.001 Keylogging T1566 Phishing T1059.005 Visual Basic T1218.004 InstallUtil T1218.009 Regsvcs/Regasm T1218 System Binary Proxy Execution T1071 Application Layer Protocol T1055 Process Injection T1055.012 Process Hollowing T1203 Exploitation for Client Execution T1555 Credentials from Password Stores T1115 Clipboard Data T1555.003 Credentials from Web Browsers T1620 Reflective Code Loading T1566.002 Spearphishing Link T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1553.002 Code Signing T1036 Masquerading T1562 Impair Defenses T1071.003 Mail Protocols T1204 User Execution T1140 Deobfuscate/Decode Files or Information T1059.010 AutoHotKey & AutoIT T1059 Command and Scripting Interpreter T1059.007 JavaScript T1105 Ingress Tool Transfer T1219 Remote Access Tools T1005 Data from Local System T1547.001 Registry Run Keys / Startup Folder T1082 System Information Discovery T1112 Modify Registry T1562.001 Disable or Modify Tools T1113 Screen Capture T1059.001 PowerShell T1003 OS Credential Dumping T1497 Virtualization/Sandbox Evasion T1016 System Network Configuration Discovery T1037 Boot or Logon Initialization Scripts T1055.001 Dynamic-link Library Injection T1070 Indicator Removal T1204.002 Malicious File T1059.003 Windows Command Shell T1622 Debugger Evasion T1057 Process Discovery T1056 Input Capture T1048 Exfiltration Over Alternative Protocol T1083 File and Directory Discovery T1070.004 File Deletion T1027.003 Steganography T1218.011 Rundll32 T1539 Steal Web Session Cookie T1497.001 System Checks T1033 System Owner/User Discovery T1564.003 Hidden Window T1125 Video Capture T1564.001 Hidden Files and Directories T1129 Shared Modules T1104 Multi-Stage Channels T1486 Data Encrypted for Impact T1547 Boot or Logon Autostart Execution T1053.005 Scheduled Task T1047 Windows Management Instrumentation T1657 Financial Theft T1016.002 Wi-Fi Discovery T1552.002 Credentials in Registry T1185 Browser Session Hijacking T1124 System Time Discovery T1087.001 Local Account T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1552.001 Credentials In Files T1649 Steal or Forge Authentication Certificates T1001 Data Obfuscation T1497.003 Time Based Checks T1012 Query Registry T1614 System Location Discovery T1547.009 Shortcut Modification T1036.001 Invalid Code Signature T1036.008 Masquerade File Type T1027.002 Software Packing T1036.003 Rename Legitimate Utilities T1027.010 Command Obfuscation T1480 Execution Guardrails T1106 Native API T1102 Web Service T1055.004 Asynchronous Procedure Call

Reporting

Research mentioning Agent Tesla

Jul 27
Netresec

PureLogs, PureRAT and misleading zgRAT

Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.

Jul 22
Security Online Info

TTF Trap: Fake Font Files Hide a Stealthy Lua Loader

A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

Jul 21
Scworld

Sophisticated crypter service Cruciferra evades detection with advanced techniques | brief | SC Media

Jul 21
Gurucul Threat Research

Unpacking โ€œCruciferraโ€: An Analysis of a Sophisticated Crypter Service | Community Portal | Gurucul

Jul 20
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

Jul 17
Gurucul Threat Research

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | Community Portal | Gurucul

Researchers reported a large-scale phishing campaign targeting Windows users with malicious archives that masquerade as business cooperation or payment-related documents from well-known companies. The infection chain uses heavily obfuscated JScript droppers and an AutoIt- or Lua-based loader disguised as a TrueType font (.ttf) file, enabling a largely fileless compromise path designed to avoid detection. Security reporting described the operation as global in scope, with lures crafted to persuade recipients to open fake font files that trigger the malware delivery process. The campaign has deployed multiple commodity malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, the latter assessed as a variant of Snake Keylogger based on shared modules and coding patterns. Researchers said the loader evolved significantly from late 2025 through mid-2026, adding anti-analysis features such as junk code, string obfuscation, API unhooking, breakpoint neutralization, Donut shellcode signature patching, decoy memory, and segmented shellcode decryption through a Vectored Exception Handler. Published indicators include domains, IP addresses, a Discord-hosted malicious JavaScript file, and SHA-256 hashes to support enterprise detection and threat hunting.

Jul 17
Cso Online

Fake TTF files deliver stealthy malware in global phishing campaign | CSO Online

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.