#agenttesla
After years of dominance in #ESET’s top #infostealer statistics, the era of #AgentTesla has come to an end. It finished H1 2025 in fourth place, its numbers having decreased by 57%. The reason? It is no longer under active development. 1/4
July 9, 2025 at 12:12 PM
#100daysofYARA - day 12
VirusTotal uses CAPE sandbox to identify many malware families and determine if they can extract the malware's configuration. Since they use CAPE, we can often see their logic. Today, we'll suggest edits to a rule for AgentTesla.

Rule at end.
1/10
January 14, 2026 at 12:38 PM
2024-12-04 (Wednesday): #AgentTesla variant using #FTP for data exfiltration. A sanitized copy of the email distributing the malware, a #pcap from an infection run, the associated malware samples, and a list of indicators are available at www.malware-traffic-analysis.net/2024/12/04/i...
December 5, 2024 at 1:15 AM
2024-11-25 (Monday): My thanks to the criminals who email malware directly to my inbox. This one is #AgentTesla using #FTP for #data_exfiltration. Sends to FTP server approx every 10 minutes.

Attached disk image file: bazaar.abuse.ch/sample/7a11d...

Extracted EXE: bazaar.abuse.ch/sample/2362b...
November 25, 2024 at 9:56 PM
2025-01-09 (Thursday): #CVE-2017-0199 #XLS --> #HTA --> #VBS --> #steganography --> #DBatLoader or #GuiLoader style malware for #AgentTesla. Data exfil over FTP. A #pcap from an infection, the associated malware, and more info available at www.malware-traffic-analysis.net/2025/01/09/i...
January 11, 2025 at 7:35 AM
2025-01-31 (Friday): Two pcaps with traffic of AgentTesla-style data exfil. One #pcap has FTP exfil, while the other has SMTP exfil. Pcaps are available at www.malware-traffic-analysis.net/2025/01/31/i...
January 31, 2025 at 9:26 PM
2025-02-12 (Wed): #VIP_Recovery (an #AgentTesla variant) from Brazil #malspam --> zip attachment --> extracted EXE.

File name: Factura Gastos.exe

Email accounts for data exfiltration: antonipont@grupobdb[.]com --> cludsewe3@gmail[.]com

EXE available at: bazaar.abuse.ch/sample/c7620...
February 12, 2025 at 5:39 PM
Hunting AgentTesla: A Deep Dive with OhMyPCAP by Jay Hawkins
www.linkedin.com/pulse/huntin...
Hunting AgentTesla: A Deep Dive with OhMyPCAP
Dont just read about malware analysis—execute it. I’ve deployed a live triage environment on KillerCoda containing a fresh AgentTesla infection.
www.linkedin.com
April 23, 2026 at 9:14 PM
2025-02-07 (Friday): Today's boring example of #malpsam pushing #GuLoader for #AgentTesla style malware. EXE of this malware available at bazaar.abuse.ch/sample/833aa...
February 7, 2025 at 9:51 PM
2025-01-09 (Thursday): Now this is more like it! Real #malspam with real #malware. Even if the infection traffic looks like it's an #Matiex or #SnakeLogger or #AgentTesla variant that exfiltrates data through api.telegram[.]org.

#AnyRun analysis of the malware EXE at: app.any.run/tasks/8ffd01...
January 9, 2025 at 5:14 AM
2026-02-03 (Tuesday): #GuLoader for #AgentTesla style malware with FTP data exfiltration. A #pcap of the infection traffic, associated files, and a list of indicators are available at www.malware-traffic-analysis.net/2026/02/03/i...
February 3, 2026 at 6:39 PM
Latest Netskope Threat Labs Report highlights Insurance industry: cloud apps serve as a conduit for half of malware downloads, with Grandoreiro banker Trojan and AgentTesla Infostealer most common #cybersecurity #threatintelligence #malwareanalysis

www.netskope.com/netskope-thr...
October 4, 2024 at 1:28 PM
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/10/01(木)
■件名
Re: 請求書
■添付ファイル
請求書.rar -> 請求書.JS virustotal.com/gui/file/e9e...
tria.ge/261002-hxfpk...
情報窃取マルウェア #AgentTesla
■C2
hxxps[:]//api.telegram[.]org/

同一メールの観測報告
x.com/tdatwja/stat...
October 2, 2026 at 1:49 PM
🔥 New videos drop! This series will take you through a full-chain analysis, from RTF and several layers of shellcode, to AutoIT script analysis and a final stage payload of AgentTesla (.net) 👇
Full-Chain Analysis - From an RTF Document to AgentTesla
This series will walk you through a full chain analysis of an RTF exploiting CVE-2017-11882 and ending with .NET malware - AgentTesla. We'll unravel to layer...
buff.ly
February 27, 2025 at 5:00 PM
Spanish speakers beware! A new campaign using the Agent Tesla RAT targets Spanish-speaking individuals.
hackread.com/phishing-cam...
#CyberSecurity #AgentTesla #Malware
New Phishing Campaign Uses Stealthy JPGs to Drop Agent Tesla
Follow us on Twitter (X) @Hackread - Facebook @ /Hackread
hackread.com
June 12, 2024 at 5:00 PM
Watch out as fake torrent for DiCaprio’s “One Battle After Another” is spreading Agent Tesla malware through malicious subtitles and hidden scripts.

Read: hackread.com/dicaprio-one...

#Cybersecurity #AgentTesla #Malware #Windows #OneBattleAfterAnother
Torrent for DiCaprio’s “One Battle After Another” Movie Drops Agent Tesla
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
December 10, 2025 at 8:29 PM
New phishing campaign delivers Agent Tesla via multi-stage, in-memory attack chain, evading detection. Stay vigilant! #CyberSecurity #Phishing #AgentTesla #Malware Link: thedailytechfeed.com/sophisticate...
February 27, 2026 at 6:44 PM
I see them.
And AgentTesla is one that triggers all the time.

The extracted "Configs" tell me it was from "VirusTotal_CAPE" so I check the CAPE GitHub to find the YARA rule for AgentTesla: github.com/kevoreill...
3/10
CAPEv2/data/yara/CAPE/AgentTesla.yar at b49b73524a136698c414acb6fc8b05ed957ec3c5 · kevoreilly/CAPEv2
Malware Configuration And Payload Extraction. Contribute to kevoreilly/CAPEv2 development by creating an account on GitHub.
github.com
January 14, 2026 at 12:38 PM
NEW: Check Point’s April 2025 malware report reveals increasingly sophisticated attacks using familiar malware like FakeUpdates, Remcos, and AgentTesla. #Education remains the top targeted sector.

Read: hackread.com/fakeupdates-...

#CyberSecurity #Malware #InfoStealers #InfoSec
FakeUpdates, Remcos, AgentTesla Top Malware Charts in Stealth Attack Surge
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 12, 2025 at 4:46 PM
La CERT-AgID riassume le campagne malevole in Italia dal 25 al 31 ottobre 2025, con malware infostealer e phishing istituzionali in aumento.

#AgentTesla #CERTAgID #Formbook
www.matricedigitale.it/2025/10/31/c...
October 31, 2025 at 4:38 PM
We reported on its functionality and observed real-world use, as well as the campaigns and malware families associated with the service.

Some details:

• Cruciferra has been delivered alongside zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos.
July 20, 2026 at 4:06 PM
Seqrite's Kirti Kshatriya analyses a malspam campaign with a steganographic stage leading to multiple stealers including Remcos, DcRAT, AgentTesla, VIPKeyLogger, etc. www.seqrite.com/blog/stegano...
March 17, 2025 at 9:27 AM
Agent Tesla hides in emoji-padded JScript, then injects straight into memory - no file ever touches disk. https://intel.threadlinqs.com/threat/TL-2026-2108 #ThreatIntel #Agent #DonutLoader #AgentTesla
August 22, 2026 at 5:37 AM
📢 darknet-mcp-server : serveur MCP open source unifiant 66 outils de threat intelligence dark web
📝 ## 🔍 Contexte

Publié sur GitHub par l'…
https://cyberveille.ch/posts/2026-07-17-darknet-mcp-server-serveur-mcp-open-source-unifiant-66-outils-de-threat-intelligence-dark-web/ #AgentTesla #Cyberveille
July 18, 2026 at 4:00 AM

Your notes hiding #malware? Cybercriminals are exploiting this popular OneNote app to deliver Redline, AgentTesla & more. Be cautious, double-check website URLs & avoid suspicious offers.
cybersecurity.att.com/blogs/labs-r...
#cybersecurity
The dark side of 2023 Cybersecurity: Malware evolution and Cyber threats
In the ever-evolving cybersecurity landscape, 2023 witnessed a dramatic surge in the sophistication of cyber threats and malware. AT&T Cybersecurity Alien Labs reviewed the big events of 2023 and how ...
cybersecurity.att.com
January 26, 2024 at 7:53 PM