ATT&CKSoftwareAgent Tesla

Agent Tesla

S0331

Malware.View on attack.mitre.org

About this malware

Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.

Techniques used37

Procedure examples37

TechniqueProcedure example
T1016
System Network Configuration Discovery

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1016.002
Wi-Fi Discovery

Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.

T1027
Obfuscated Files or Information

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1033
System Owner/User Discovery

Agent Tesla can collect the username from the victim’s machine.

T1047
Windows Management Instrumentation

Agent Tesla has used wmi queries to gather information from the system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1053.005
Scheduled Task

Agent Tesla has achieved persistence via scheduled tasks.

T1055
Process Injection

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055.012
Process Hollowing

Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code.

T1056.001
Keylogging

Agent Tesla can log keystrokes on the victim’s machine.

T1057
Process Discovery

Agent Tesla can list the current running processes on the system.

T1071.001
Web Protocols

Agent Tesla has used HTTP for C2 communications.

T1071.003
Mail Protocols

Agent Tesla has used SMTP for C2 communications.

T1082
System Information Discovery

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1087.001
Local Account

Agent Tesla can collect account information from the victim’s machine.

View all 37 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. Bitdefender Agent Tesla April 2020 Open source
    Arsene, L. (2020, April 21). Oil & Gas Spearphishing Campaigns Drop Agent Tesla Spyware in Advance of Historic OPEC+ Deal. Retrieved May 19, 2020.
  2. Fortinet Agent Tesla April 2018 Open source
    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.
  3. Malwarebytes Agent Tesla April 2020 Open source
    Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.