ATT&CKReferencesBitdefender Agent Tesla April 2020

Bitdefender Agent Tesla April 2020

Arsene, L. (2020, April 21). Oil & Gas Spearphishing Campaigns Drop Agent Tesla Spyware in Advance of Historic OPEC+ Deal. Retrieved May 19, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareAgent Tesla

Agent Tesla has used wmi queries to gather information from the system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1185
Browser Session Hijacking
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

T1204.002
Malicious File
MalwareAgent Tesla

Agent Tesla has been executed through malicious e-mail attachments

T1555.003
Credentials from Web Browsers
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

T1566.001
Spearphishing Attachment
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.