Agent Tesla - Daily Threat Report

Sunday, July 5, 2026

Daily Summary

Today saw 61 new Agent Tesla samples, a 24% rise over the 7-day average of 49, driven primarily by a surge in JavaScript-based droppers. While no new C2 servers were identified, the shift in initial infection vectors warrants attention.

New Samples Detected

The file type distribution is the most notable change today, with JavaScript (.js) files making up 39% of all samples (24 out of 61), compared to a historical average of roughly 20%. This is a clear pivot away from the usual macro-laden Office documents and compiled executables. The presence of a single .35189119 extension suggests an automated packer or obfuscation script, potentially generating randomized filenames to evade hash-based blacklists. The support for less common archive formats like .r01 and .tar indicates the operators are testing alternative compression methods to bypass email attachment filters that specifically block .zip and .rar.

7-Day Trend

At +24%, today’s volume exceeds the 7-day average but does not reach the 25% threshold for a full trend section. The surge is notable due to the distinct file type shift rather than raw volume alone, suggesting a tactical adjustment rather than a broad expansion of the campaign.

IOC Highlights

All 61 new samples are classified as IOCs, though no new C2 infrastructure was identified today. Analysts should prioritize the 24 .js hashes for immediate blocking, as these files represent the primary delivery mechanism for this uptick. The single .xls sample deserves scrutiny, as it may indicate a targeted variant or a low-velocity complementary attack vector.

Security Analysis

The disproportionate rise in JavaScript droppers against the backdrop of no new C2 servers suggests Agent Tesla operators are refining their initial access phase rather than establishing fresh command nodes. This may indicate they are reusing existing C2 infrastructure to validate a new delivery method. Defensive teams should tighten email gateway rules to block .js attachments outright or enforce execution through a sandbox, as script-based payloads often bypass standard signature detection and depend on user interaction to download the final payload.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Agent Tesla Reports

Recent Malware Reports