Infostealer
Agent Tesla
Infostealer
29 detections found
Also known as: AgentTesla, Negasteal
Agent Tesla is a .NET-based remote access trojan/spyware active since 2014, sold commercially and widely pirated/cracked for criminal use rather than run as a formal MaaS platform. It is primarily delivered via phishing attachments (malicious Office macros, OLE objects, and CHM files) and harvests browser and application credentials (e.g., FileZilla, Outlook, OpenVPN), keystrokes, clipboard data, and screenshots, exfiltrating over SMTP, FTP, or HTTP. There has been no law-enforcement takedown of Agent Tesla; it remains one of the most consistently observed malware families in circulation and was named among CISA's top malware strains.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- Agent Tesla, Software S0331 — MITRE ATT&CK
- Inside the Mind of a 'Rat' - Agent Tesla Detection and Analysis — Splunk
- 2021 Top Malware Strains (AA22-216A) — CISA