Malware.View on attack.mitre.org
Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings. |
| T1016.002 Wi-Fi Discovery |
Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1027 Obfuscated Files or Information |
Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings. |
| T1033 System Owner/User Discovery |
Agent Tesla can collect the username from the victim’s machine. |
| T1047 Windows Management Instrumentation |
Agent Tesla has used wmi queries to gather information from the system. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1053.005 Scheduled Task |
Agent Tesla has achieved persistence via scheduled tasks. |
| T1055 Process Injection |
Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055.012 Process Hollowing |
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1056.001 Keylogging |
Agent Tesla can log keystrokes on the victim’s machine. |
| T1057 Process Discovery |
Agent Tesla can list the current running processes on the system. |
| T1071.001 Web Protocols |
Agent Tesla has used HTTP for C2 communications. |
| T1071.003 Mail Protocols |
Agent Tesla has used SMTP for C2 communications. |
| T1082 System Information Discovery |
Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1087.001 Local Account |
Agent Tesla can collect account information from the victim’s machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.