Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Agent Tesla is Windows information-stealing malware, and recent reports show how campaigns have varied the ways they deliver it and try to avoid analysis. FortiGuard Labs’ February 25, 2026 report describes one campaign that used a purchase-order email, a multi-stage script-and-PowerShell chain, in-memory payload execution and checks for virtualized or security-analysis environments. These are findings from that sample—not a checklist of features present in every Agent Tesla infection.

How does Agent Tesla get onto a computer?

In the campaigns discussed here, the attackers relied on email attachments and layered delivery: an attachment starts a loader, which retrieves or unlocks later code. The particular lure, file type, scripting language and payload-loading method vary by campaign.

FortiGuard Labs: RAR attachment and JScript downloader, February 2026

FortiGuard Labs analyzed a Windows campaign using a business-themed purchase-order email. Its RAR attachment contained an obfuscated JScript file with the .jse extension. The script fetched an encrypted PowerShell stage from a file-hosting service; later stages decrypted and executed .NET payloads in memory. FortiGuard identified the final payload as Agent Tesla. FortiGuard Labs’ campaign analysis describes this chain as one sample’s behavior.

HP Wolf Security: macro-enabled Word documents, December 2025

A separate report described fake purchase-order Word documents sent to companies in Asia. The documents asked recipients to enable editing and macros. The macro downloaded PowerShell, and layered code ran in memory before injecting a decoded payload into the legitimate AddInProcess32 process. HP Wolf Security identified the payload as Agent Tesla and reported credential and other data theft. This is a distinct delivery path, not an additional stage in FortiGuard’s campaign. HP Wolf Security’s December 2025 report provides its findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

CERT-AGID: encrypted .NET loader in an Italian campaign, December 2024

CERT-AGID reported an Italian email campaign in which an initial attachment failed because a required delimiter string was missing. A later sample contained AES-encrypted .NET code; its loader decrypted and loaded Agent Tesla directly into memory. CERT-AGID said this loader differed from the resource-based approach it usually observed. The failed attachment and later working sample belong to this campaign’s timeline, not to the 2026 FortiGuard sample. CERT-AGID’s December 2, 2024 notice documents the Italian case.

Sophos: chunked payloads and additional evasion options, February 2021

Sophos described two circulating Agent Tesla versions that used a .NET downloader to retrieve payload chunks from legitimate third-party sites, then join, decode and decrypt them. The report also described attempts to modify Microsoft’s Antimalware Scan Interface (AMSI), plus options involving Tor and Telegram for command and control. These are historical findings from Sophos’ 2021 analysis; they are not evidence that FortiGuard’s 2026 sample used the same methods. Sophos’ report sets out those earlier variants.

What new tricks does Agent Tesla use to evade detection?

The 2026 FortiGuard sample checked its environment before proceeding. It used Windows Management Instrumentation (WMI) for virtualization checks and scanned for DLLs associated with security and sandbox products. FortiGuard reported that the sample could stop when those checks suggested it was running in a researcher or sandbox environment. This behavior can make automated analysis less straightforward, but it should not be generalized to every Agent Tesla build.

Other reports describe different ways to complicate inspection: Sophos reported AMSI modification attempts in 2021, while the 2024 CERT-AGID and 2025 HP Wolf Security cases described loaders that decrypted or ran payloads in memory. FortiGuard’s 2026 report also described process hollowing of a legitimate Windows process. These are separate observations across campaigns and dates, not proof of a single upgrade sequence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MITRE ATT&CK’s Agent Tesla profile indexes observed behaviors including email attachment delivery, obfuscation, process injection and hollowing, virtualization and sandbox evasion, and several forms of credential theft and data collection. A behavior listed there is one that has been observed; it does not mean all samples use it. The profile was last modified April 16, 2025. MITRE ATT&CK: Agent Tesla (S0331).

How do the reported campaigns differ?

The comparison below keeps the reports separate. “Not stated” means the cited report, as summarized here, does not establish that detail; it does not imply the technique was absent.

Report and context Initial lure and attachment Loader and payload handling Reported evasion or execution behavior Communications or data handling
FortiGuard Labs, February 25, 2026; Windows campaign Business purchase-order email; RAR containing obfuscated JScript .jse JSE fetched encrypted PowerShell from a file-hosting service; later stages decrypted and ran .NET payloads in memory WMI virtualization checks, scans for security and sandbox DLLs, process hollowing; sample could stop in researcher or sandbox environments Collected browser cookies and contacts; sent stolen information using SMTP
HP Wolf Security, December 2025; companies in Asia Fake purchase-order Word document asking recipients to enable editing and macros Macro downloaded PowerShell; layered code ran in memory and injected a decoded payload into AddInProcess32 In-memory execution and process injection; further anti-analysis checks not stated Credential and other data theft; specific exfiltration channel not stated
CERT-AGID, December 2, 2024; Italian email campaign Email attachment; an initial sample failed due to a missing required delimiter string Later sample contained AES-encrypted .NET code; loader decrypted and loaded Agent Tesla into memory, differing from CERT-AGID’s commonly observed resource-based approach Direct in-memory loading; other checks not stated Specific communications or exfiltration channel not stated
Sophos, February 2021; two circulating versions Email delivery; attachment details not stated in the cited summary .NET downloader fetched chunks hosted on legitimate third-party sites, then joined, decoded and decrypted them Attempts to modify AMSI; options involving Tor and Telegram Tor and Telegram described as command-and-control options

Can Agent Tesla steal saved passwords or browser data?

Yes. FortiGuard reported that its 2026 sample collected browser cookies and contacts and sent stolen information by SMTP. Across observed Agent Tesla behavior, MITRE ATT&CK also lists credential theft, keylogging, clipboard theft and screenshots. Those capabilities are documented across samples, not guaranteed in every infection. HP Wolf Security separately reported credential and other data theft in its 2025 campaign.

For defenders, the practical implication is that an attachment’s apparent file type or a lack of an obvious payload on disk cannot alone establish that a device is safe. The cited campaigns include staged downloads, in-memory loading and process manipulation, but the specific chain differs from one report to another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I do about a suspicious purchase-order attachment?

If you received the message

  • Do not open an unexpected archive or document, and do not enable macros or editing because an attachment asks you to.
  • Verify the purchase order with the sender through a phone number or contact method you already trust—not details supplied in the suspicious message.
  • If you already opened it or enabled content, disconnect the device from networks if your organization’s policy directs you to, and contact your IT or security team promptly. Avoid deleting files or attempting cleanup before responders can assess the device.
  • From a separate, known-clean device, change passwords for accounts that may have been used on the affected computer, prioritizing email and business accounts; revoke active sessions where the service allows it.

For organizations

  • Use email attachment screening and controls for risky archive, script and macro-enabled document types, with a process for safely handling legitimate exceptions.
  • Apply email authentication and user education so staff can recognize unexpected purchase-order requests and verify them independently.
  • Monitor endpoints for suspicious script execution, unexpected PowerShell activity, in-memory execution and process injection or hollowing. Endpoint detection should complement—not replace—attachment controls and incident response.
  • Maintain a clear reporting route for suspected phishing and an incident-response process for isolating devices, preserving evidence and resetting exposed credentials.

Sophos recommends general protections such as attachment screening and user awareness; these measures reduce risk but cannot guarantee that every variant will be blocked. FortiGuard’s listed hashes and campaign infrastructure are time-sensitive indicators, useful only when checked against current, trusted threat intelligence; they are not durable standalone defenses.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.