Agent Tesla
Qu'est-ce que Agent Tesla ?
Agent TeslaA .NET-based remote access trojan and information stealer active since 2014, sold openly as a commercial product and distributed primarily through phishing emails carrying malicious Office documents and archive attachments.
Agent Tesla is a .NET-based info-stealer and remote-access trojan that has been continuously active since 2014, sold openly as a 'monitoring' product on its own clearnet site and through reseller channels. It exists in dozens of slightly different versions because affiliates routinely repack the binary. Capabilities include keystroke logging, clipboard capture, screenshot capture, webcam access, theft of browser passwords and cookies, mail client credentials (Outlook, Thunderbird, FoxMail), VPN client credentials, FTP credentials, and exfiltration over SMTP, FTP, HTTP, or Telegram bots. The dominant infection vector is phishing email: lure documents embed Equation Editor (CVE-2017-11882, CVE-2018-0802) exploits or contain malicious archive attachments delivering a loader stage. Agent Tesla is one of the longest-running commodity stealers and routinely tops monthly malware ranking reports from anti-spam vendors, especially in business-email-compromise-adjacent campaigns. Defenses include disabling Office Equation Editor, attachment-detonation sandboxes, and EDR detections on the common loader behaviors (process hollowing into RegSvcs.exe, AspNetCompiler.exe).
● Exemples
- 01
A phishing email with subject 'PURCHASE ORDER' delivers a .iso containing an Agent Tesla loader that exfiltrates Outlook stored credentials via SMTP.
- 02
An EDR rule alerts on RegSvcs.exe making outbound SMTP connections to a non-corporate mail server — a near-pathognomonic Agent Tesla pattern.
● Questions fréquentes
Qu'est-ce que Agent Tesla ?
A .NET-based remote access trojan and information stealer active since 2014, sold openly as a commercial product and distributed primarily through phishing emails carrying malicious Office documents and archive attachments. Cette notion relève de la catégorie Logiciels malveillants en cybersécurité.
Que signifie Agent Tesla ?
A .NET-based remote access trojan and information stealer active since 2014, sold openly as a commercial product and distributed primarily through phishing emails carrying malicious Office documents and archive attachments.
Comment fonctionne Agent Tesla ?
Agent Tesla is a .NET-based info-stealer and remote-access trojan that has been continuously active since 2014, sold openly as a 'monitoring' product on its own clearnet site and through reseller channels. It exists in dozens of slightly different versions because affiliates routinely repack the binary. Capabilities include keystroke logging, clipboard capture, screenshot capture, webcam access, theft of browser passwords and cookies, mail client credentials (Outlook, Thunderbird, FoxMail), VPN client credentials, FTP credentials, and exfiltration over SMTP, FTP, HTTP, or Telegram bots. The dominant infection vector is phishing email: lure documents embed Equation Editor (CVE-2017-11882, CVE-2018-0802) exploits or contain malicious archive attachments delivering a loader stage. Agent Tesla is one of the longest-running commodity stealers and routinely tops monthly malware ranking reports from anti-spam vendors, especially in business-email-compromise-adjacent campaigns. Defenses include disabling Office Equation Editor, attachment-detonation sandboxes, and EDR detections on the common loader behaviors (process hollowing into RegSvcs.exe, AspNetCompiler.exe).
Comment se défendre contre Agent Tesla ?
Les défenses contre Agent Tesla combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.
Quels sont les autres noms de Agent Tesla ?
Noms alternatifs courants : AgentTesla, OriginLogger (rebrand).
● Termes liés
- malware№ 591
Info stealer
Logiciel malveillant qui collecte identifiants, cookies, jetons, portefeuilles crypto et autres données sensibles d'un appareil infecté pour les exfiltrer.
- malware№ 254
Voleur de credentials
Logiciel malveillant axé sur l'extraction de mots de passe, de hash et de jetons d'authentification depuis un système infecté ou sa mémoire.
- malware№ 660
Enregistreur de frappe (keylogger)
Logiciel ou matériel qui enregistre les touches frappées par un utilisateur, employé pour voler mots de passe, données financières ou messages.
- malware№ 1023
Cheval de Troie d'accès à distance (RAT)
Logiciel malveillant qui donne à un attaquant un contrôle furtif et interactif d'un appareil infecté, similaire à un outil caché d'administration à distance.
- attacks№ 1191
Hameçonnage ciblé (spear phishing)
Attaque d'hameçonnage ciblée et personnalisée visant une personne ou une organisation précise à partir de renseignements collectés au préalable.
- attacks№ 152
Compromission de messagerie d'entreprise
Fraude ciblée où un attaquant usurpe ou prend le contrôle d'une boîte mail d'entreprise pour pousser un employé à virer de l'argent, modifier des coordonnées bancaires ou exfiltrer des données.