216.73.216.6

Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign

· Published 25/02/2026 20:01 · Modified 25/02/2026 20:56

Export JSON

Essential information

Published
25/02/2026 20:01
Modified
25/02/2026 20:56
Tags
2026-02-25 agent-tesla anti-analysis credential harvesting data exfiltration in-memory execution multi-stage attack phishing process-hollowing smtp
Related entities
4 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 others

Description

This analysis examines a sophisticated multi-stage infection chain utilizing Agent Tesla malware. The attack begins with a email containing a RAR file, which includes an obfuscated JSE file. This initial stage triggers a series of script-based evasions, leading to the download and decryption of a PowerShell script. The malware then employs process hollowing to inject its payload into a legitimate Windows process, evading detection. Before exfiltrating data, the malware performs checks to avoid security software and virtual environments. Finally, Agent Tesla harvests sensitive information, including browser cookies and contacts, exfiltrating the data via to a command-and-control server.

External references