Skip to content
Detecteam
  • CompanyExpand
    • Founders Story
    • The Team
  • ProductExpand
    • About Us
  • SolutionsExpand
    • Use Cases
  • ResourcesExpand
    • Detecteam Blogs
    • Contact Us
Twitter Linkedin
Detecteam
Blog · Scenario

Agent Tesla RAT

Avatar photoByDetecteam 2023-08-102023-08-10

TLP

TLP CLEAR

Author

Sebastien TRICAUD

Summary

Agent Tesla RAT is a potent remote access trojan designed to infiltrate systems discreetly. Employed by threat actors, it facilitates unauthorized access to compromised systems, enabling data theft, surveillance, and control. Operating since 2014, it is notorious for its keylogging capabilities, recording keystrokes to gather sensitive information like passwords and credentials. Agent Tesla employs various distribution methods, often exploiting phishing emails and malicious attachments. Once activated, it evades detection through encryption, frequently altering its code to bypass security measures. Its multifunctional nature, including screen capturing and file exfiltration, makes it a preferred choice for cyber espionage and criminal activities.

DATA

windows_sysmon_nxlog.json_Download

TIMELINE

CATEGORY

Malware

references

  • https://www.zscaler.com/blogs/security-research/agent-tesla-rat-delivered-quantum-builder-new-ttps

MITRE ATT&CK

Post Tags: #T1041 - Exfiltration Over C2 Channel#T1053.005 - Scheduled Task/Job: Scheduled Task#T1056 - Input Capture#T1059.001 - Command and Scripting Interpreter: PowerShell#T1113 - Screen Capture#T1204 - User Execution#T1218.003 - CMSTP#T1218.009 - Regsvcs/Regasm#T1547.001 - Registry Run Keys / Startup Folder#T1548.002 - Abuse Elevation Control Mechanism: Bypass User Account Control#T1566.001 - Phishing: Spearphishing Attachment
Avatar photo
Detecteam
X

Detecteam is transforming cybersecurity detection from static rule-writing to autonomous, continuous validation. Our REFLEX platform automates the detection lifecycle—building, testing, validating and deploying detections in minutes, not months. We help enterprises maximize ROI on existing tools, close high-risk detection gaps faster, and scale security outcomes without scaling headcount. This is the future of detection-as-code, and we’re leading it.

CONTACT US

Detecteam Inc.
300 Lenora Street PMB 659
Seattle, WA 98121 USA
+1 (650) 542-0831
sales@detecteam.com

  • Privacy Policy

SOCIAL MEDIA

Twitter Linkedin
OUR NEWSLETTER

Check your inbox or spam to confirm your subscription.

© 2025 Detecteam Inc. All Rights Reserved.

  • Company
    • Founders Story
    • The Team
  • Product
    • About Us
  • Solutions
    • Use Cases
  • Resources
    • Detecteam Blogs
    • Contact Us
Search