Malware
Agent Tesla
Also known as: AgenTesla · AgentTesla · Negasteal
A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
Indicators of Compromise 2
MITRE ATT&CK TTPs 12
T1006 T1012 T1014 T1053.005 T1055 T1055.015 T1068 T1070.004 T1071.001 T1082 T1204.002 T1548.002
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
ListPlanting
Defense Evasion
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Web Protocols
Command And Control
System Information Discovery
Discovery
Malicious File
Execution
Bypass User Account Control
Privilege Escalation