Netskope Threat Labs

Agent Tesla

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Agent Tesla is a remote access trojan written for the .NET framework that has circulated as a sold product since at least 2014. It captures keystrokes, clipboard contents, and saved passwords from web browsers and applications, and it can take screenshots and exfiltrate the collected data over SMTP, FTP, or HTTP. Cyberattackers typically deliver it through phishing emails with malicious attachments, and its buyer base treats it as malware as a service, which keeps the family in constant circulation.

First seen
January 2022
Last seen
October 2026
AgentTeslaAgentTeslaFEMAgenteslaPacker

37 techniques across 10 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol
    • T1048.003Exfiltration Over Unencrypted Non-C2 Protocol

TA0112 Defense Impairment

Alert Name
AIT:Trojan.AgentTesla.1085
AIT:Trojan.AgentTesla.1212
ByteCode-MSIL.Backdoor.AgentTesla
ByteCode-MSIL.Dropper.AgentTesla
ByteCode-MSIL.Infostealer.AgentTesla
ByteCode-MSIL.Trojan.AgenteslaPacker
ByteCode-MSIL.Trojan.AgentTesla
ByteCode-MSIL.Trojan.AgentTeslaFEM
Document-HTML.Trojan.AgentTesla
Document-Office.Trojan.AgentTesla