Cohesity REDLab has released updates to its threat library in response to renewed activity related to Agent Tesla which is a Remote Access Trojan (RAT) and credential stealer. The Center for Internet Security (CIS) recently added Agent Tesla to its TOP 10 malware list for Q3 of 2025. Agent Tesla has evolved into one of the most prevalent malware families targeting organizations worldwide. First observed in 2014, Agent Tesla is written in .NET and is widely distributed via phishing campaigns, malicious attachments, and exploit kits. Its adaptability and modular design make it a persistent threat to enterprise environments, especially as attackers refine delivery techniques to bypass modern defenses.
Agent Tesla is a full-featured RAT with the following capabilities:
2025 saw a surge in sophisticated Agent Tesla campaigns employing multi-stage delivery chains. Attackers use layered scripts and payloads to evade static and behavioral detection. For example, recent campaigns targeted global sectors (like finance, manufacturing, and education) using WeTransfer-themed lures and QR code phishing tactics.
Targeted campaigns have been observed against organizations in the United States, Australia, Taiwan, and Mexico. Attackers leverage business email databases and compromised accounts to maximize infection rates.
New loaders like QuirkyLoader facilitate DLL side-loading and process hollowing, further complicating detection and response.
Cohesity’s REDLab is a fully isolated, in-house security lab dedicated to validating cyber resilience against real-world threats. REDLab simulates attacks using live malware, including Agent Tesla, to benchmark detection accuracy and recovery capabilities. Key REDLab contributions include:
Agent Tesla exemplifies the evolving sophistication of malware targeting enterprises. Its modular design, credential theft capabilities, and multi-stage delivery chains demand adaptive, intelligence-driven defenses. Cohesity REDLab’s proactive research and validation provide organizations with the tools and insights needed to detect, respond to, and recover from Agent Tesla and similar threats.
For the latest advisories and technical details, visit Cohesity REDLab.
Start your 30-day free trial or view one of our demos.