Agenttesla

Category: infostealer · Aliases: aitesla, negasteal · Sample count (EMBER 2018): 43 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

AgentTesla is a prolific commodity information-stealer and keylogger written in .NET, in continuous development since 2014. It harvests credentials from over 70 applications including browsers, email clients, FTP clients, and VPN software, and exfiltrates data via email, FTP, or HTTP. AgentTesla is one of the most commonly observed malware families in business email compromise campaigns, typically delivered through phishing with malicious Office attachments or archive files.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1566.001 T1056.001 T1071.001 T1555.003

Frequently Asked Questions

What is Agenttesla?

AgentTesla is a prolific commodity information-stealer and keylogger written in .NET, in continuous development since 2014. It harvests credentials from over 70 applications including browsers, email clients, FTP clients, and VPN software, and exfiltrates data via email, FTP, or HTTP. AgentTesla is one of the most commonly observed malware families in business email compromise campaigns, typically delivered through phishing with malicious Office attachments or archive files.

How does Agenttesla spread?

Agent Tesla is delivered primarily through phishing emails carrying weaponized Office documents, ISO images, or compressed archives, often using malicious macros or exploits to drop the payload.

What are the signs of an Agenttesla infection?

Common signs include unexpected outbound SMTP, FTP, or Telegram traffic for credential exfiltration, browser password-manager prompts, and antivirus alerts referencing Agent Tesla or Negasteal.

What should I do if I think I have Agenttesla on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/agenttesla.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.