This malware abuses Tor and Telegram infrastructure to evade detection

Skull and Bones
(Image credit: Pixabay)

For more than seven years, the Agent Tesla family of remote access trojan (RAT) malware has remained one of the most common threats to Windows users online as it is continually updated by its creators.

A variety of cybercriminals leverage the malware to steal user credentials and other information through screenshots, keylogging and clipboard capture. However, as Agent Tesla's compiler hard-codes operator-specific variables when its built, the malware's behavior can vary widely as it continues to evolve.

According to Sophos, recent changes to the malware increased the number of applications targeted for credential theft to include web browsers, email clients, VPN clients and other software that stores usernames and passwords.

SophosLabs has tracked multiple threat actors using Agent Tesla and as of December of last year, it accounted for 20 percent of malicious email attachments detected in the company's customer telemetry.

Agent Tesla v3

In its new report on Agent Tesla, Sophos sheds further light on two currently active versions of the malware identified as version 2 and version 3 to show how the RAT has evolved by using multiple types of defense evasion and obfuscation to avoid detection.

While both versions of the malware can be configured to communicate over HTTP, SMTP and FTP, version 3 adds the Telegram chat protocol as an option so that attackers can exfiltrate stolen data to a private Telegram chat room.

At the same time, Agent Tesla v3 also allows an attacker to decide whether or not they wish to deploy a Tor client to conceal their communications and this version of the malware can even steal the contents of the Windows system clipboard.

As malicious spam is the most common delivery method for Agent Tesla, Sophos recommends that organizations and individuals treat email attachments from unknown senders with caution and verify the integrity of attachments before opening them.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost