Agent Tesla - Daily Threat Report

Sunday, August 16, 2026

By Yazoul AI · automated

Daily Summary

Agent Tesla activity surged on 2026-08-16 with 100 new samples, a 44% increase over the 7-day average of 69. The most notable shift is the dominant role of JavaScript-based loaders, which account for nearly half of all new samples, while traditional executable payloads have receded to second place.

New Samples Detected

The file type distribution has shifted materially. JavaScript files lead with 46 samples (46%), followed by executables at 34 (34%). Supporting roles are filled by VBScript (6), Excel add-ins (5 combined .xla and .xlam), HTA (3), VBE (2), and single entries for .cmd, .bat, and a rare .14492 extension. The .14492 extension is unusual and may indicate an automated obfuscation tool generating randomized file extensions to bypass extension-based filtering in email gateways.

The JavaScript-heavy mix suggests a campaign strategy of layering: JS loaders fetch and execute the final Agent Tesla payload in memory, reducing the need for on-disk executables. The presence of Excel add-ins alongside JS and HTA points to a multipronged phishing suite rather than a single template.

Distribution Methods

The blend of script types strongly implies phishing emails as the primary delivery mechanism. The high JS count, combined with Office add-in files, is consistent with campaigns using zipped attachments or OneDrive/SharePoint links that host the initial dropper. The single .cmd and .bat files indicate some attackers are still testing classic command-line execution paths, likely for smaller, targeted waves.

7-Day Trend

The 44% deviation from the 7-day average exceeds the 25% threshold and warrants attention. This is not a gradual climb but a sharp single-day jump, suggesting a coordinated spam burst rather than organic growth in malware distribution. SOC teams should expect elevated phishing traffic for the next 48 to 72 hours as these campaigns typically run in waves.

IOC Highlights

All 100 new samples have associated IOCs, though no new C2 infrastructure was registered today. The absence of fresh C2 domains suggests the operators are reusing existing infrastructure, which makes blocking by domain reputation less effective. The IOCs predominantly consist of hashes and the URLs embedded in the JavaScript loaders. Analysts should prioritize extracting the callback URLs from the JS samples, as these point to the actual staging servers.

Security Analysis

The dominance of JavaScript loaders in this surge mirrors the evolution seen in other credential-stealing malware families, where the initial stage is increasingly a lightweight, polymorphic script rather than a compiled binary. This shifts the detection burden to script execution and behavior monitoring rather than static file scanning. The reuse of existing C2 infrastructure despite a 44% sample surge indicates the operator is scaling distribution without investing in new infrastructure, a sign of a mature, cost-optimized operation.

Actionable recommendation: Deploy a script-blocking policy for email attachments that quarantines JavaScript, HTA, and VBE files unless explicitly allowlisted, and enable AMSI-based behavioral detection on hosts to catch in-memory execution of Agent Tesla payloads that bypass traditional file-based signatures.

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Agent Tesla Reports

Recent Malware Reports