S0331: Agent Tesla
Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.CitationFortinet Agent Tesla April 2018CitationBitdefender Agent Tesla April 2020CitationMalwarebytes Agent Tesla April 2020
Security context for executives and security teams
Agent Tesla matters because it is a Windows .NET spyware Trojan associated in ATT&CK with credential and user activity collection behaviors such as keylogging, screen capture, clipboard access, video capture, discovery, command-and-control, and exfiltration techniques. For leaders, the practical issue is not the malware name alone; it is whether Windows endpoint, identity, email, and network controls can prove they would expose credential theft and data collection before stolen access creates wider business risk.
Executive priority
Prioritize this as a validation case for endpoint visibility, credential protection, phishing-driven malware response, and incident evidence quality. ATT&CK links Agent Tesla to groups including SilverTerrier and TA2541, with TA2541 described as using high-volume campaigns and commodity remote access tools in aviation, aerospace, transportation, manufacturing, and defense contexts. Executives should ask whether the organization can rapidly determine which users, credentials, hosts, and outbound channels were exposed if spyware is found on a Windows endpoint.
Technical view
SOC and IR teams should validate coverage against the ATT&CK-linked behaviors rather than relying on a malware family signature. Confirm visibility for Windows process creation, .NET execution artifacts, WMI activity, scheduled task creation, registry modification, process injection or hollowing indicators, local account and system discovery, Wi-Fi discovery, keylogging-related suspicious access patterns, screen or clipboard capture, outbound web and mail protocol communications, ingress tool transfer, and possible unencrypted exfiltration. Because MITRE provides no official detection text for this object, detection engineering should map local analytics to the related techniques and test whether telemetry is retained long enough for credential-exposure scoping.
Likely telemetry
- Windows endpoint process creation and command-line telemetry
- EDR events for process injection, process hollowing, and suspicious child processes
- Windows Scheduled Task and Task Scheduler operational logs
- Windows Registry modification events
- WMI activity and related process execution records
Detection direction
- Build detections around behavior chains: discovery followed by persistence, collection, outbound communications, or exfiltration is more meaningful than any single generic command.
- Tune WMI, scheduled task, and registry alerts for unusual parent processes, user context, file paths, recurrence, and proximity to suspicious executable or .NET activity.
- Correlate keylogging, screen capture, clipboard access, or video capture signals with outbound web or mail protocol traffic to reduce false positives from legitimate administration or collaboration software.
- Monitor for suspicious use of mail protocols and web protocols from endpoints that do not normally initiate such traffic directly.
- Treat process injection and process hollowing detections as high-value triage pivots, but validate against legitimate security, management, and software update tools that may create noise.
Mitigation priorities
- Harden Windows endpoints first: maintain endpoint protection, application control where feasible, least privilege, and controls that restrict unauthorized persistence through scheduled tasks and registry changes.
- Reduce credential exposure by enforcing MFA, monitoring risky sign-ins, rotating credentials when spyware exposure is confirmed, and limiting local account reuse.
- Improve egress control by restricting unnecessary direct outbound web and mail protocol use from workstations and logging allowed paths.
- Limit abuse of administrative features such as WMI through least privilege, administrative segmentation, and monitoring of remote or unusual use.
- Strengthen email and attachment defenses as part of readiness, while recognizing this object’s supplied ATT&CK fields do not define a specific delivery method.
Additional notes and limits
Agent Tesla is represented here as a Windows .NET spyware Trojan observed since at least 2014. ATT&CK relationships provide the main defensive value: they connect the malware to discovery, credential access, collection, persistence, defense evasion, command-and-control, ingress transfer, and exfiltration techniques. The SilverTerrier and TA2541 relationships are useful threat-intelligence context but should not be treated as proof of attribution in any local incident without supporting evidence.
The supplied ATT&CK object has no official detection section, no object-level tactics, no aliases, and limited platform detail beyond Windows. Several related techniques list broader platforms, but Agent Tesla should not be treated as supported on those platforms based only on this object. Local telemetry, malware samples, delivery evidence, and environment-specific baselines are required to make detection, exposure, or attribution claims.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Agent Tesla
Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.CitationFortinet Agent Tesla April 2018CitationBitdefender Agent Tesla April 2020CitationMalwarebytes Agent Tesla April 2020
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
