Overview
Agent Tesla is a .NET-based spyware Trojan and remote access tool that has been sold as malware-as-a-service since at least 2014. MITRE ATT&CK tracks it as software S0331 and links its use to the SilverTerrier Nigerian business-email-compromise cluster and the phishing group TA2541. It is one of the longest-running commodity keyloggers still in active distribution, and its leaked builder has spawned a direct successor, OriginLogger, which reuses Agent Tesla's code and configuration handling so closely that many Agent Tesla detection rules still catch it.
Agent Tesla is not a ransomware precursor loader in the way some infostealers are. It is a self-contained keylogger and credential harvester built around a single subscription-based builder. Affiliates configure their own phishing lure, C2 channel, and exfiltration protocol, then distribute the resulting binary independently. This makes every Agent Tesla sample slightly different at the byte level while the underlying behavior, credential harvesting, keystroke logging, screenshot capture, and mail/HTTP/FTP/Telegram exfiltration, stays consistent across builds.
The malware's staying power comes from low barrier to entry rather than technical novelty. HHS's Health Sector Cybersecurity Coordination Center documented Agent Tesla campaigns exploiting Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2017-8570 during a 2020 wave of COVID and PPE-themed phishing; the underlying exploitation and phishing patterns are still in use, with only the thematic wrapper changing. Recent campaign reporting from sandbox analysis describes business-document lures, purchase orders, invoices, payroll files, and procurement requests, replacing the pandemic-era themes.
Agent Tesla is not used for lateral movement or ransomware deployment. It is a single-host credential and surveillance tool. Its downstream risk comes from what happens to the harvested data: stolen mailbox and VPN credentials feed business email compromise, and law enforcement action, including Interpol arrests tied to Agent Tesla-assisted financial crime, has repeatedly connected the malware to BEC fraud rings operating out of West Africa.