logo

Malware Analysis: What is Agent Tesla?

ID: be5e63d4-0ee5-5f3e-9e41-82e470061a06

STIX ID: report--be5e63d4-0ee5-5f3e-9e41-82e470061a06

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2020-07-30

Date Updated: 2026-04-29

...
...

This report describes Agent Tesla, a .NET remote access trojan actively distributed in COVID‑19 themed phishing campaigns using RTF attachments that exploit CVE‑2017‑11882 to execute a payload which injects into RegAsm.exe to steal credentials, keystrokes, and perform form‑grabbing; it highlights observed filenames, affected sectors (healthcare, government, finance), and recommends mitigations including patching, user training, RBAC, and improved detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.