Remote Access Trojan

Agent Tesla

First seen: 2014-01 • Status: active

Currently Active Threat

Agent Tesla is a spy program that records everything you type on your keyboard and takes screenshots of what you do. It's been around since 2014 and is sold as 'monitoring software' but criminals use it to steal passwords and spy on victims. It typically arrives through business email scams pretending to be invoices or shipping notices.

Overview

Agent Tesla is a .NET-based remote access trojan (RAT) and keylogger that has been active since 2014. It is sold as a legitimate "monitoring software" but is primarily used for malicious purposes. Agent Tesla is one of the most common malware families distributed via phishing campaigns targeting businesses.

Also Known As

AgentTesla, Negasteal

How It Spreads

  • Business Email Compromise (BEC) phishing campaigns
  • Fake invoice and shipping notification emails
  • Malicious Office documents with macros
  • Compressed archives with executables
  • Exploit kits (CVE-2017-11882 commonly used)

What It Does

  • Records all keystrokes (keylogging)
  • Captures screenshots at regular intervals
  • Steals credentials from email clients and browsers
  • Monitors clipboard contents
  • Exfiltrates data via SMTP, FTP, or HTTP
  • Captures webcam photos

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Monitor for processes using common keylogging APIs
  • Alert on .NET processes making SMTP connections
  • Detect screenshot capture API calls from unusual processes
  • Watch for processes adding themselves to startup
  • Monitor for clipboard monitoring behavior

MITRE ATT&CK Techniques

T1056.001, T1113, T1555, T1041, T1547.001

If You're Infected

  1. 1.

    Kill the Agent Tesla process and isolate the system

  2. 2.

    Assume all typed passwords are compromised - reset immediately

  3. 3.

    Check for and remove persistence mechanisms in startup

  4. 4.

    Review email accounts for unauthorized access or rules

  5. 5.

    Scan other systems for lateral movement

  6. 6.

    Train employees on business email phishing tactics

Related Malware

Formbook, Hawkeye, Remcos

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required