Agent Tesla - Daily Threat Report

Sunday, July 19, 2026

Daily Summary

Agent Tesla activity surged on 2026-07-19 with 89 new samples detected, a 33% increase over the 7-day average of 67. The primary driver was a steep rise in JavaScript-based loaders, which accounted for 57% of today’s samples. No new C2 infrastructure was observed, suggesting operators are reusing existing servers.

New Samples Detected

The file type distribution shifted dramatically today. JavaScript files (54 samples, including .js and .xls variants) dominated, representing a 75% increase from the 7-day average of 31 JS-based samples. Traditional executable payloads (.exe) fell to 20 samples, while archive-based delivery (.rar, .tgz, .zip) collectively contributed 10 samples. Notably, a single .hta file was observed, consistent with the low-volume use of HTA in spear-phishing campaigns. The presence of .xls and .xlsx files (3 total) suggests continued use of macro-laden Office documents, though JS remains the primary infection vector.

Detection Rate

Despite the sample surge, no new C2 servers were registered, which may indicate that attackers are cycling through existing infrastructure to evade signature-based detection. The heavy reliance on JavaScript loaders, a known Agent Tesla hallmark, suggests that signature-based AV products with up-to-date JS detection rules should flag these samples. However, SOC analysts should verify that their detections for encoded or obfuscated JS are tuned, as out-of-the-box rules often miss heavily obfuscated .js files.

7-Day Trend

Today’s 89 samples mark a 33% increase over the 7-day average of 67, and a 62% increase from the daily low of 55 samples observed on 2026-07-13. The trendline is clearly rising, with the last three days averaging 82 samples per day. This sustained uptick warrants heightened alerting for JS downloads and process hollowing from wscript.exe or cscript.exe.

IOC Highlights

All 89 new samples are associated with first-seen hashes and filenames, but no new C2 domains or IPs were recorded. The IOCs cluster around JavaScript loader filenames such as invoice_*.js, package_*.js, and shipping_*.js, which are consistent with ongoing phishing campaigns targeting shipping and logistics personnel. A single .tgz sample named FedEx_Shipping_Details.tgz further reinforces this theme.

Security Analysis

The absence of new C2 servers combined with a 33% sample surge is notable. It implies that Agent Tesla operators are not broadening their infrastructure footprint, but are instead intensifying distribution through a stable server set. This pattern often correlates with credential harvesting campaigns where stolen data is exfiltrated to previously registered servers to avoid the operational cost of procuring new domains. Defenders should prioritize blocking all JS attachments with shipping or invoice themes and enforce execution policies that prevent wscript.exe and cscript.exe from spawning child processes without explicit approval.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Agent Tesla Reports

Recent Malware Reports