ATT&CKReferencesMalwarebytes Agent Tesla April 2020

Malwarebytes Agent Tesla April 2020

Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016.002
Wi-Fi Discovery
MalwareAgent Tesla

Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.

T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1140
Deobfuscate/Decode Files or Information
MalwareAgent Tesla

Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm.

T1497
Virtualization/Sandbox Evasion
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

T1555
Credentials from Password Stores
MalwareAgent Tesla

Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles.

T1564.003
Hidden Window
MalwareAgent Tesla

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.