What is Agent Tesla?
Agent Tesla is a .NET-based keylogger and information stealer that harvests credentials from browsers, email and FTP clients, and logs keystrokes, screenshots and clipboard data. It exfiltrates over SMTP, FTP and Telegram, and is delivered through phishing attachments, making it one of the most prolific commodity stealers since it first appeared around 2014.
Why track it with PrecisionSec
- Multi-channel credential and keystroke theft. Agent Tesla siphons passwords, keystrokes and screenshots out over SMTP, FTP and Telegram. Block its infrastructure before data leaves the building.
- Cut commodity-malware noise. High-confidence classification lets your SOC filter mass-distributed crimeware and focus on targeted, hands-on threats.
- Built for your stack. Delivered via STIX/TAXII, MISP, CSV and REST API.
Agent Tesla C2 and distribution IOCs are included in every PrecisionSec intelligence subscription. See Infostealer Intelligence for malware hashes and infrastructure IOCs across the infostealer activity PrecisionSec discovers.