Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Infostealer

Agent Tesla

Infostealer 29 detections found

Also known as: AgentTesla, Negasteal

Agent Tesla is a .NET-based remote access trojan/spyware active since 2014, sold commercially and widely pirated/cracked for criminal use rather than run as a formal MaaS platform. It is primarily delivered via phishing attachments (malicious Office macros, OLE objects, and CHM files) and harvests browser and application credentials (e.g., FileZilla, Outlook, OpenVPN), keystrokes, clipboard data, and screenshots, exfiltrating over SMTP, FTP, or HTTP. There has been no law-enforcement takedown of Agent Tesla; it remains one of the most consistently observed malware families in circulation and was named among CISA's top malware strains.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
splunk Windows File Transfer Protocol In Non-Common Process Path production 2026-06-25
splunk Cisco Secure Firewall - Intrusion Events by Threat Activity production 2026-05-13
splunk Windows Mail Protocol In Non-Common Process Path production 2026-05-13
suricata ET MALWARE Agent Tesla CnC Exfil via TCP rev 1 2025-07-10
snort ET TROJAN Agent Tesla CnC Exfil via TCP rev 1 2025-07-10
sigma Disable Internal Tools or Feature in Registry test 2025-06-04
suricata ET MALWARE AgentTesla PWS HTTP CnC Checkin rev 7 2024-04-30
suricata ET MALWARE Observed AgentTesla Domain Request rev 6 2024-04-13
sigma Registry Explorer Policy Modification test 2023-08-17
sigma Registry Hide Function from User test 2023-08-17
sigma Testing Usage of Uncommonly Used Port test 2022-01-23
snort ET TROJAN Win32/AgentTesla Variant Exfil via Telegram rev 2 2020-08-27
suricata ET MALWARE Win32/AgentTesla Variant Exfil via Telegram rev 1 2020-08-27
suricata ET MALWARE AgentTesla Exfil Via SMTP rev 1 2020-05-18
snort ET TROJAN AgentTesla Exfil Via SMTP rev 2 2020-05-18
suricata ET MALWARE AgentTesla Exfil via FTP rev 1 2020-04-16
suricata ET MALWARE AgentTesla HTML System Info Report Exfil via FTP rev 1 2020-04-16
snort ET TROJAN AgentTesla Exfil via FTP rev 2 2020-04-16
snort ET TROJAN AgentTesla HTML System Info Report Exfil via FTP rev 1 2020-04-16
snort ET TROJAN Win32/Agent Tesla SMTP Clipboard Exfil rev 2 2019-11-18
suricata ET MALWARE Win32/Agent Tesla SMTP Clipboard Exfil rev 1 2019-11-18
snort ET TROJAN Observed AgentTesla Domain Request rev 2 2019-08-28
suricata ET MALWARE Agent Tesla Keylogger Report SMTP rev 3 2019-07-26
snort ET TROJAN Agent Tesla Keylogger Report SMTP rev 2 2017-05-18
snort ET TROJAN AgentTesla PWS HTTP CnC Checkin rev 3 2016-12-19
yara agenttesla_smtp_variant — —
yara Agenttesla — —
yara Agenttesla_type1 — —
yara Agenttesla_type2 — —