ATT&CKReferencesTalos Agent Tesla Oct 2018

Talos Agent Tesla Oct 2018

Brumaghin, E., et al. (2018, October 15). Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1125
Video Capture
MalwareAgent Tesla

Agent Tesla can access the victim’s webcam and record video.

T1560
Archive Collected Data
MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.