Agent Tesla - Daily Threat Report

Sunday, August 9, 2026

By Yazoul AI · automated

Daily Summary

Yazoul Security’s malware tracker recorded 90 new Agent Tesla samples today, a 33% increase over the 7-day average of 68. The rise is driven entirely by a surge in JavaScript-based loaders, which account for 79 of the 90 samples and represent a notable shift from the typical EXE-heavy distribution we have observed in recent weeks.

New Samples Detected

The file-type distribution this cycle is unusual. JavaScript files dominate at 79 samples (88%), with only 6 native executables, 2 VBS scripts, and single instances of .xls, .vbe, and .uue formats. The presence of a .uue file (UUencoded attachment) and the .vbe sample suggests operators are testing legacy encoding and obfuscation paths, likely to bypass email gateway filters that now routinely block .js attachments. The single .xls file indicates a residual macro-based delivery thread, but it is clear the campaign’s primary push is through script-based loaders that fetch the final payload from remote hosts.

Naming patterns in today’s batch are worth noting: the majority of .js samples use randomized 8-character filenames with no discernible theme, a deviation from the invoice- and shipment-related names seen in the prior week’s campaign. This suggests a new builder or packing service is in use, or the operators are deliberately avoiding predictable naming to reduce heuristic detection.

Analysis

The spike in JavaScript loaders aligns with a broader trend we are tracking across multiple malware families: threat actors are increasingly abandoning macro-enabled Office documents in favor of script-based delivery due to improved macro blocking in Microsoft 365. Agent Tesla operators appear to have adopted this tactic en masse starting this week. The zero new C2 servers registered today is notable, as it suggests the infrastructure is stable and operators are reinvesting in distribution rather than expanding command-and-control capacity.

From a defensive standpoint, the immediate priority should be tightening email security rules to quarantine .js attachments with randomized filenames, particularly those arriving with ZIP or ISO wrappers. Additionally, SOC teams should review endpoint detection rules for PowerShell or WScript execution chains that initiate outbound HTTP requests to non-standard ports, as these JavaScript loaders typically download the Agent Tesla binary from dynamic URI patterns that are refreshed every few hours. Blocking script execution from user-writable directories (e.g., %TEMP% and %APPDATA%) will neutralize most of today’s samples before they can execute the final payload.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Agent Tesla Reports

Recent Malware Reports