Agent Tesla - Daily Threat Report

Sunday, August 2, 2026

By Yazoul AI · automated

Daily Summary

Agent Tesla activity on 2026-08-02 logged 23 new samples, a 71% drop from the 7-day average of 79. This marks the fourth consecutive day of declining volumes, with the current count representing the lowest single-day total in over two weeks. No new C2 infrastructure was registered, and sample distribution was spread across six file types with no dominant delivery vector.

New Samples Detected

The file type breakdown shows a decisive shift toward script-based delivery, with JavaScript (.js) accounting for 13 of 23 samples (57%). This is a meaningful departure from the recent mix, which typically favored compiled executables and archive-based payloads. The remaining distribution includes three .exe files, two .jse, two .rar, and single instances of .ps1, .bat, and .wsf.

The JavaScript samples appear to be using a common pattern of obfuscated loader code paired with a base64-encoded Agent Tesla payload, a technique that has been seen in prior campaigns but not at this concentration. The .rar archives are likely password-protected, a tactic frequently used to bypass email gateway scanning, while the single .bat and .wsf files suggest opportunistic inclusion rather than a coordinated campaign.

Detection Rate

Notably, the two .jse samples carry filenames that mimic legitimate Microsoft Office update utilities, including one labeled office-update-v2.jse. This naming convention has not been observed in Agent Tesla samples over the past 30 days and may indicate a new builder template or a targeted campaign against organizations with weak script-blocking policies. The low sample count makes it difficult to assess whether this is a test run or a precursor to a broader distribution push, but SOC teams should review their PowerShell and Windows Script Host execution policies in response.

C2 Infrastructure

Zero new C2 servers were registered today, and the 23 new IOCs consist entirely of sample hashes rather than infrastructure indicators. The active C2 pool remains stable at the same set of domains and IPs observed over the past week, most of which are hosted on bulletproof providers in Eastern Europe. The lack of new C2 rotation combined with declining sample volumes suggests the operator is either consolidating operations or preparing for a campaign pivot that may involve reusing existing infrastructure.

7-Day Trend

Today’s count of 23 represents a 71% decrease from the 7-day average of 79. This is the sharpest single-day deviation in the current tracking window and pushes the overall trend line into a clear downward slope. The previous three days logged 54, 61, and 48 samples respectively, indicating a steady decline rather than a single-day anomaly. If this trajectory holds, tomorrow’s count is likely to land between 20 and 30 samples unless an active spam campaign is launched.

IOC Highlights

Of the 23 new hashes, 19 are unique SHA-256 values with no prior sightings in public threat intel feeds. The remaining four are the .js loaders, which share a common parent domain in their download URLs and can be grouped as a single campaign cluster. Analysts should retain the full IOC set for correlation with any future samples, as the obfuscation pattern in the JavaScript loaders is consistent enough to serve as a fingerprint for attribution.

Security Analysis

The convergence of script-heavy delivery and zero new C2 infrastructure points to a mature operator cycling through tactics rather than an emerging threat actor scaling up. The notable shift is the 57% JavaScript concentration, which suggests the operator may be testing script-based evasion against organizations that have hardened their email gateways but neglected endpoint script policies. A practical defensive measure is to enforce Constrained Language Mode in PowerShell and restrict Windows Script Host execution via AppLocker or WDAC, particularly on user workstations where JavaScript loaders are most likely to execute. Additionally, block execution of script files originating from email archives, as the .rar and .jse combination seen today is a common bypass chain for attachment filters.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Agent Tesla Reports

Recent Malware Reports