Remote Access Trojan
Agent Tesla
First seen: 2014-01 • Status: active
Currently Active Threat
Agent Tesla is a spy program that records everything you type on your keyboard and takes screenshots of what you do. It's been around since 2014 and is sold as 'monitoring software' but criminals use it to steal passwords and spy on victims. It typically arrives through business email scams pretending to be invoices or shipping notices.
Overview
Agent Tesla is a .NET-based remote access trojan (RAT) and keylogger that has been active since 2014. It is sold as a legitimate "monitoring software" but is primarily used for malicious purposes. Agent Tesla is one of the most common malware families distributed via phishing campaigns targeting businesses.
Also Known As
AgentTesla, Negasteal
How It Spreads
- • Business Email Compromise (BEC) phishing campaigns
- • Fake invoice and shipping notification emails
- • Malicious Office documents with macros
- • Compressed archives with executables
- • Exploit kits (CVE-2017-11882 commonly used)
What It Does
- • Records all keystrokes (keylogging)
- • Captures screenshots at regular intervals
- • Steals credentials from email clients and browsers
- • Monitors clipboard contents
- • Exfiltrates data via SMTP, FTP, or HTTP
- • Captures webcam photos
Is your business exposed?
Target Platforms
Windows 7, Windows 10, Windows 11
Detection Tips
- • Monitor for processes using common keylogging APIs
- • Alert on .NET processes making SMTP connections
- • Detect screenshot capture API calls from unusual processes
- • Watch for processes adding themselves to startup
- • Monitor for clipboard monitoring behavior
MITRE ATT&CK Techniques
T1056.001, T1113, T1555, T1041, T1547.001
If You're Infected
- 1.
Kill the Agent Tesla process and isolate the system
- 2.
Assume all typed passwords are compromised - reset immediately
- 3.
Check for and remove persistence mechanisms in startup
- 4.
Review email accounts for unauthorized access or rules
- 5.
Scan other systems for lateral movement
- 6.
Train employees on business email phishing tactics
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required