Malware Analysis: What is Agent Tesla?
ID: be5e63d4-0ee5-5f3e-9e41-82e470061a06
STIX ID: report--be5e63d4-0ee5-5f3e-9e41-82e470061a06
Feed Name: ReliaQuest Blog
Threat Score
This report describes Agent Tesla, a .NET remote access trojan actively distributed in COVID‑19 themed phishing campaigns using RTF attachments that exploit CVE‑2017‑11882 to execute a payload which injects into RegAsm.exe to steal credentials, keystrokes, and perform form‑grabbing; it highlights observed filenames, affected sectors (healthcare, government, finance), and recommends mitigations including patching, user training, RBAC, and improved detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
